Pin GoReleaser and gate the generated Homebrew cask in CI - #511
Merged
Merged
Conversation
2 tasks
Base automatically changed from
devx-1124-homebrew-cask-generated-tap-warning-switch-hookspostinstall
to
main
September 22, 2026 10:01
2 tasks
joe4dev
force-pushed
the
devx-1124-guard-generated-homebrew-cask
branch
2 times, most recently
from
September 22, 2026 10:39
75fb741 to
dd3f443
Compare
joe4dev
force-pushed
the
devx-1124-guard-generated-homebrew-cask
branch
2 times, most recently
from
September 22, 2026 12:56
be579b7 to
607b035
Compare
Co-Authored-By: Claude <noreply@anthropic.com>
joe4dev
force-pushed
the
devx-1124-guard-generated-homebrew-cask
branch
from
September 22, 2026 14:02
607b035 to
260bb75
Compare
joe4dev
marked this pull request as ready for review
September 22, 2026 16:04
anisaoshafi
approved these changes
Sep 23, 2026
anisaoshafi
left a comment
Collaborator
There was a problem hiding this comment.
Thanks for taking this measure to avoid similar future issues with goreleaser <> homebrew. LGTM! 🚀
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Nothing in this repo reads the generated Homebrew cask. Only a release writes it, and it lands in a tap with no CI, so a bad cask first surfaces as a user's
brew install. That is how the deprecatedpostflightstanza shipped and survived two releases (#510, localstack/homebrew-tap#7).Two things made that possible, and this PR closes both.
Solution
Pin GoReleaser.
version: "~> v2"floated, so a GoReleaser minor could change the published cask with no change in this repo..tool-versionsnow pinsgoreleaser 2.18.2, and both the check and release jobs read it through the action'sversion-file:— the same pattern the repo already uses for golangci-lint. A version bump becomes a reviewable diff, and mise/asdf users get the pinned version locally.scripts/check-cask.shenforces the same pin, asmake lintdoes for golangci-lint.Gate the cask, in two halves.
make check-caskrenders it through a snapshot release and asserts what we care about: no deprecated raw-Ruby flight stanza, the quarantine step survives, it targets the whole staged dir with{{staged_path}}intact. Runs last ingoreleaser-check, after the cheap checks, ~165s.make lint-caskthen runs Homebrew's own linters, which catch deprecations nobody here thought to look for —Cask/InstallStepsis the cop that flags the stanza #510 fixed.brew styleandbrew audit --cask, through a throwaway tap, since audit refuses a bare path and the cask cops only apply to a file underCasks/.The two are split because Homebrew is not on the Linux runners, which I found the hard way on the first CI run here (
brew required on PATH). So a newcask-lintjob onmacos-latestdownloads the cask the Linux job rendered and lints those exact bytes, rather than rendering a second time that could diverge. It is deliberately not in thereleasejob'sneeds:yet — the same staged rollout govulncheck is on.The script stubs the bundle (
fetch-bundled-extensions.sh --stub, per docs/extensions-bundling.md), since thebundled/globs are live and the real fetch needs a private-repo token. The job gainedsetup-goandinstall-only: true, having never built anything before.Temporarily skipped style checks
brew styleruns with--except-cops=Cask/StanzaOrder. #510'scustom_blockrenders the stanza at the top of the cask, so every stanza after it is reported out of order — 9 offences on the generated cask, all from that one cop.The exception is scoped to that cop alone, and I verified it does not blind the gate: run against the old published cask,
brew style --except-cops=Cask/StanzaOrderstill fails withCask/InstallSteps: Casks must use postflight_steps instead of postflight.A
TODO(#512)on the line records the removal. #512 moves the stanza tohooks.post.install_steps, which renders it in place —brew styleis then clean with no exception, confirmed against a build of goreleaser/goreleaser#6873.Validation
uninstall_postflightblockgoreleaser 2.99.0 required (found: 2.18.2)Two gates, not one
This gate runs before a release exists, which bounds what it can see: a rendered cask's
urlpoints at an unpublished release and itssha256are of locally built archives, so neither can be verified here.brew audit --online, the form that fetches every url and checks every checksum, is therefore impossible in this repo.localstack/homebrew-tap#10 adds that missing half — the last check before users install, run against the artifact as published. The two are complementary:
Worth knowing about
brew audithere: offline it passes both the fixed and the deprecated cask, so it would not have caught this bug —brew styleis what does. It is in this PR for other classes of fault.Docs
Nothing to document. No new or changed command, flag, env var, or output.
make check-caskis a contributor-facing target, covered by the script's own header; the GoReleaser pin is release tooling.Review
Human review advised: it changes the release job's GoReleaser resolution and adds a build step to every PR.
Todo
--except-cops=Cask/StanzaOrderwhen Use hooks.post.install_steps for the cask quarantine step #512 landsTowards DEVX-1124
🤖 Generated with Claude Code