Skip to content

feat(ci): publish Scoop manifests after releases - #39

Merged
jmgilman merged 1 commit into
mainfrom
feat/scoop-publish-workflow
Aug 21, 2026
Merged

jmgilman merged 1 commit into
mainfrom
feat/scoop-publish-workflow

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • add a default-off reusable Scoop publisher that verifies the release artifact and signed bundle before minting a bucket-scoped App token
  • carry Scoop controls through the Actions artifact while excluding both package-manager controls from signed/public GitHub Release payloads
  • run Scoop and Homebrew publication independently after the public GitHub Release and document the workflow, credential, output, and control-file contracts

Verification

  • actionlint on all five changed workflows, ignoring only the repository's established $/.github/actions/setup-release-cli parser limitation and pre-existing ShellCheck notices
  • mise exec -- goreleaser check
  • mise exec -- moon run root:check
  • structural YAML assertions for disabled credentials, job ordering, permissions, dependencies, output states, and control isolation
  • GoReleaser snapshot produced exactly one Homebrew cask and one Scoop manifest; both Windows archive hashes matched the generated manifest

@jmgilman
jmgilman merged commit 38fde4f into main Aug 21, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant