Repository navigation
Add split release artifacts and Homebrew packages - #16
Conversation
📝 WalkthroughWalkthroughThe release process now produces separate combined and CLI installers, app and tarball artifacts, validates signed outputs, creates immutable GitHub Releases, and dispatches Homebrew metadata. Version 0.3.1 metadata, installer templates, documentation, and build-status presentation were updated. ChangesRelease distribution
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related issues
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Around line 167-178: Update the README release workflow description to state
that it creates a new immutable GitHub Release, removing the claim that it
creates or updates an existing release. Keep the surrounding publishing and
verification details unchanged.
- Around line 19-48: Add Homebrew lifecycle documentation to the README
installation section, covering tap setup and verified commands for installing,
upgrading, and uninstalling both the CLI formula and macOS app cask. Clearly
identify which Homebrew artifact each command manages, while preserving the
existing signed package and ZIP installation guidance.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro Plus
Run ID: e61c6bcb-cdcf-452c-a776-bcb7a2d91646
📒 Files selected for processing (13)
.github/workflows/release.ymlREADME.mdSwiftpkgr/Screens/BuildView.swiftVERSIONrelease/SwiftpkgCLIInstaller/.gitignorerelease/SwiftpkgCLIInstaller/README.mdrelease/SwiftpkgCLIInstaller/build-info.plistrelease/SwiftpkgCLIInstaller/payload/.gitkeeprelease/SwiftpkgInstaller/README.mdrelease/SwiftpkgInstaller/build-info.plistscripts/publish-xcode-release.shswiftpkg.xcodeproj/project.pbxprojswiftpkg/Version.swift
💤 Files with no reviewable changes (1)
- .github/workflows/release.yml
| Download `SHA256SUMS` and the appropriate signed, notarized artifact from the | ||
| matching GitHub Release: | ||
|
|
||
| Verify the download before installation: | ||
| - `swiftpkg-<version>-combined.pkg` installs both the CLI and Swiftpkgr and | ||
| requires macOS 15 or later. | ||
| - `swiftpkg-<version>-cli.pkg` installs only the CLI and requires macOS 13 or | ||
| later. | ||
| - `Swiftpkgr-<version>.zip` contains only the macOS 15+ app. | ||
|
|
||
| Verify a package download before installation: | ||
|
|
||
| ```sh | ||
| shasum -a 256 -c SHA256SUMS | ||
| pkgutil --check-signature swiftpkg-<version>-universal.pkg | ||
| xcrun stapler validate swiftpkg-<version>-universal.pkg | ||
| sudo installer -pkg swiftpkg-<version>-universal.pkg -target / | ||
| grep ' swiftpkg-<version>-combined.pkg$' SHA256SUMS | shasum -a 256 -c - | ||
| pkgutil --check-signature swiftpkg-<version>-combined.pkg | ||
| xcrun stapler validate swiftpkg-<version>-combined.pkg | ||
| sudo installer -pkg swiftpkg-<version>-combined.pkg -target / | ||
| swiftpkg --version | ||
| ``` | ||
|
|
||
| The installer places the executable at `/usr/local/bin/swiftpkg` and the app at | ||
| `/Applications/Swiftpkgr.app`. Deploy that same installer through Munki, Jamf | ||
| Pro, or another management system; do not repackage its contents. Subsequent | ||
| releases replace the CLI and atomically upgrade the app bundle. | ||
| The combined installer places the executable at `/usr/local/bin/swiftpkg` and | ||
| the app at `/Applications/Swiftpkgr.app`. Deploy that artifact through Munki, | ||
| Jamf Pro, or another management system; do not repackage its contents. Use the | ||
| CLI package when managed Macs do not need the app. The ZIP can be expanded and | ||
| `Swiftpkgr.app` moved to `/Applications` for an app-only installation. | ||
|
|
||
| To uninstall, remove `/usr/local/bin/swiftpkg` and | ||
| `/Applications/Swiftpkgr.app`, then optionally forget the | ||
| `com.codecarton.swiftpkg.installer` receipt after confirming it is not needed | ||
| for inventory. | ||
| `com.codecarton.swiftpkg.installer` or | ||
| `com.codecarton.swiftpkg.cli.installer` receipt after confirming it is not | ||
| needed for inventory. |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Document the Homebrew lifecycle.
This installation section omits Homebrew install, upgrade, and uninstall instructions for the new formula and cask. Add the verified tap commands and clarify which artifact each command manages. As per PR objectives, “The README must document Homebrew installation, upgrades, and uninstallation.”
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` around lines 19 - 48, Add Homebrew lifecycle documentation to the
README installation section, covering tap setup and verified commands for
installing, upgrading, and uninstalling both the CLI formula and macOS app cask.
Clearly identify which Homebrew artifact each command manages, while preserving
the existing signed package and ZIP installation guidance.
| CLI and app products from Xcode, signs and notarizes them, and builds the | ||
| combined and CLI-only installers with the `swiftpkg` in `PATH`. It writes both | ||
| packages, the stapled app ZIP, the Homebrew CLI tarball, and `SHA256SUMS` to | ||
| `dist/`, pushes `main` and the explicit `v<version>` tag, and creates or updates | ||
| the GitHub Release. Once those signed assets are published, it dispatches the | ||
| immutable CLI and app URLs and checksums to `codecarton/homebrew-tap`, where | ||
| automation opens one tested formula-and-cask update pull request. The dispatch | ||
| token should be limited to that tap repository. | ||
|
|
||
| Only the trusted signing workflow creates the immutable GitHub Release. See | ||
| [VERIFICATION.md](VERIFICATION.md), [CONTRIBUTING.md](CONTRIBUTING.md), and | ||
| [SECURITY.md](SECURITY.md) for project processes. |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Describe release creation as create-only.
Line 170 says the workflow “creates or updates” a GitHub Release, but scripts/publish-xcode-release.sh fails when one already exists and always calls gh release create. State that it creates a new immutable release.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` around lines 167 - 178, Update the README release workflow
description to state that it creates a new immutable GitHub Release, removing
the claim that it creates or updates an existing release. Keep the surrounding
publishing and verification details unchanged.
Summary
Swiftpkgr.appZIP for Homebrew Caskswiftpkgformulacodecarton/homebrew-tapThe official tap now renders and validates both
Formula/swiftpkg.rbandCasks/swiftpkgr.rbin one automated update PR.Relates to #3 once the signed 0.3.1 release is published and its generated tap PR
is verified and merged.
Closes #17
Release artifacts
swiftpkg-<version>-combined.pkgswiftpkg-<version>-cli.pkgSwiftpkgr-<version>.zipswiftpkg-<version>-universal.tar.gzSHA256SUMSSafety
Only the trusted local signing workflow publishes releases or dispatches
Homebrew updates; no tag-triggered unsigned workflow remains. The publisher
validates signatures, notarization, stapling, package payload separation,
archived app version, and immutable checksums before dispatch.
Validation
swift test./scripts/verify-loop.shsh -n scripts/publish-xcode-release.shswiftpkgandSwiftpkgrbrew stylefor generated formula and caskbrew audit --strictfor generated formula and caskgit diff --checkThe final signed
--buildand Homebrew install checks require the trustedrelease credentials and published 0.3.1 assets, so they remain release-time
acceptance checks.
Summary by CodeRabbit
New Features
Bug Fixes
Documentation
Release