Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
88 changes: 87 additions & 1 deletion .github/workflows/go-pre-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,28 @@ name: Reusable Go Pre-publish

on:
workflow_call:
inputs:
sign-and-notarize-macos:
description: Sign and notarize Darwin binaries before archiving.
required: false
default: false
type: boolean
secrets:
macos-sign-p12:
description: Base64-encoded Developer ID Application certificate.
required: false
macos-sign-password:
description: Password for the Developer ID Application certificate.
required: false
macos-notary-key:
description: Base64-encoded App Store Connect API private key.
required: false
macos-notary-key-id:
description: App Store Connect API key ID.
required: false
macos-notary-issuer-id:
description: App Store Connect API issuer ID.
required: false
outputs:
artifact-id:
description: ID of the authoritative release-assets artifact.
Expand All @@ -28,7 +50,7 @@ jobs:
release-assets:
name: Build authoritative release assets
runs-on: ubuntu-24.04
timeout-minutes: 20
timeout-minutes: 30
outputs:
artifact-id: ${{ steps.upload.outputs.artifact-id }}
artifact-url: ${{ steps.upload.outputs.artifact-url }}
Expand All @@ -44,6 +66,33 @@ jobs:
GOTOOLCHAIN: local
MISE_EXEC_AUTO_INSTALL: 'false'
steps:
- name: Validate macOS signing configuration
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
ENABLED: ${{ inputs.sign-and-notarize-macos }}
MACOS_SIGN_P12: ${{ secrets.macos-sign-p12 }}
MACOS_SIGN_PASSWORD: ${{ secrets.macos-sign-password }}
MACOS_NOTARY_KEY: ${{ secrets.macos-notary-key }}
MACOS_NOTARY_KEY_ID: ${{ secrets.macos-notary-key-id }}
MACOS_NOTARY_ISSUER_ID: ${{ secrets.macos-notary-issuer-id }}
with:
script: |
if (process.env.ENABLED !== 'true') {
return
}

const required = [
'MACOS_SIGN_P12',
'MACOS_SIGN_PASSWORD',
'MACOS_NOTARY_KEY',
'MACOS_NOTARY_KEY_ID',
'MACOS_NOTARY_ISSUER_ID',
]
const missing = required.filter((name) => !process.env[name])
if (missing.length !== 0) {
core.setFailed(`macOS signing is enabled but these credentials are missing: ${missing.join(', ')}`)
}

- name: Require a tag ref
shell: bash
run: |
Expand Down Expand Up @@ -92,6 +141,12 @@ jobs:
- name: Stage Go release artifacts
env:
RELEASE_CLI: ${{ steps.setup-cli.outputs.cli-path }}
MACOS_NOTARIZE_ENABLED: ${{ inputs.sign-and-notarize-macos }}
MACOS_SIGN_P12: ${{ secrets.macos-sign-p12 }}
MACOS_SIGN_PASSWORD: ${{ secrets.macos-sign-password }}
MACOS_NOTARY_KEY: ${{ secrets.macos-notary-key }}
MACOS_NOTARY_KEY_ID: ${{ secrets.macos-notary-key-id }}
MACOS_NOTARY_ISSUER_ID: ${{ secrets.macos-notary-issuer-id }}
shell: bash
run: |
set -euo pipefail
Expand All @@ -110,6 +165,36 @@ jobs:
RELEASE_GORELEASER_PATH="${goreleaser_path}" \
mise exec -- "${RELEASE_CLI}" stage --profile go --dist dist

- name: Set up Homebrew
id: homebrew
if: hashFiles('dist/homebrew/Casks/*.rb') != ''
uses: Homebrew/actions/setup-homebrew@8f3d1ec8a696b3b9d9a6c3696b6c73033cab69e4 # 2026.08.14.1
with:
brew-gh-api-token: ''

- name: Format generated Homebrew casks
if: steps.homebrew.outcome == 'success'
env:
HOMEBREW_NO_AUTO_UPDATE: '1'
shell: bash
run: |
set -euo pipefail
tap='meigma/release-build'
tap_root=''
cleanup() {
if [ -n "${tap_root}" ]; then
brew untap --force "${tap}" >/dev/null
fi
}
trap cleanup EXIT

brew tap-new --no-git "${tap}"
tap_root="$(brew --repository "${tap}")"
cp dist/homebrew/Casks/*.rb "${tap_root}/Casks/"
brew style --fix --cask "${tap}"
brew style --cask "${tap}"
cp "${tap_root}"/Casks/*.rb dist/homebrew/Casks/

- name: Upload canonical Linux binaries
id: upload-oci-input
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down Expand Up @@ -137,6 +222,7 @@ jobs:
dist/*.sbom.json
dist/checksums.txt
dist/checksums.txt.sigstore.json
dist/homebrew/Casks/*.rb
if-no-files-found: error
retention-days: 7
compression-level: 0
8 changes: 8 additions & 0 deletions .github/workflows/publish-github-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,14 @@ jobs:
path: dist
digest-mismatch: error

- name: Exclude Homebrew control from GitHub Release
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
script: |
const fs = require('fs/promises')
const path = require('path')
await fs.rm(path.resolve('dist/homebrew'), {recursive: true, force: true})

- name: Verify authoritative release bundle
id: bundle
env:
Expand Down
Loading