From 93b1c97d9e259ebda93f72b7f22a074a23e6ca82 Mon Sep 17 00:00:00 2001 From: Fedor Korotkov Date: Mon, 6 Jul 2026 13:05:54 -0400 Subject: [PATCH] Publish Softnet releases to homebrew-tools --- .github/workflows/release.yml | 32 ++++++++++++++++++++++++++++---- .goreleaser.yml | 8 ++++++-- 2 files changed, 34 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 061f79d..399abda 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,26 +7,44 @@ on: workflow_dispatch: permissions: - contents: write + contents: read jobs: release: name: ${{ github.ref_type == 'tag' && 'Release' || 'Release (Dry Run)' }} runs-on: ghcr.io/cirruslabs/macos-runner:tahoe + environment: publish timeout-minutes: 60 - env: - GITHUB_TOKEN: ${{ secrets.GH_PAT }} - GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} steps: - uses: actions/checkout@v6 with: fetch-depth: 0 + persist-credentials: false - name: Install Rust run: | curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal echo "$HOME/.cargo/bin" >> "$GITHUB_PATH" - name: Install release targets run: rustup target add aarch64-apple-darwin x86_64-apple-darwin + - name: Create release app token for this repo + if: github.ref_type == 'tag' + id: app-token + uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + with: + app-id: ${{ secrets.RELEASE_APP_ID }} + private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} + permission-contents: write + - name: Create release app token for homebrew-tools + if: github.ref_type == 'tag' + id: tap-token + uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + with: + app-id: ${{ secrets.RELEASE_APP_ID }} + private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} + owner: openai + repositories: homebrew-tools + permission-contents: write + permission-pull-requests: write - name: Release if: github.ref_type == 'tag' uses: goreleaser/goreleaser-action@v7 @@ -34,6 +52,10 @@ jobs: distribution: goreleaser-pro version: "~> v2" args: release --clean + env: + GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} + HOMEBREW_TAP_GITHUB_TOKEN: ${{ steps.tap-token.outputs.token }} + GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} - name: Release dry run if: github.ref_type != 'tag' uses: goreleaser/goreleaser-action@v7 @@ -41,6 +63,8 @@ jobs: distribution: goreleaser-pro version: "~> v2" args: release --skip=publish --snapshot --clean + env: + GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} - name: Upload dry-run artifacts if: github.ref_type != 'tag' uses: actions/upload-artifact@v6 diff --git a/.goreleaser.yml b/.goreleaser.yml index 8b9b094..53b873a 100644 --- a/.goreleaser.yml +++ b/.goreleaser.yml @@ -23,8 +23,12 @@ release: brews: - name: "{{ .ProjectName }}" repository: - owner: cirruslabs - name: homebrew-cli + owner: openai + name: homebrew-tools + token: "{{ .Env.HOMEBREW_TAP_GITHUB_TOKEN }}" + branch: "softnet-{{ .Version }}" + pull_request: + enabled: true caveats: See the Github repository for more information homepage: https://github.com/openai/softnet description: Software networking with isolation for Tart