Skip to content

Add split release artifacts and Homebrew packages - #16

Merged
jordancalhoun merged 3 commits into
mainfrom
feature/homebrew
Jul 18, 2026
Merged

jordancalhoun merged 3 commits into
mainfrom
feature/homebrew

Conversation

@jordancalhoun

@jordancalhoun jordancalhoun commented Jul 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • publish separate signed combined and CLI-only installer packages
  • publish a stapled Swiftpkgr.app ZIP for Homebrew Cask
  • retain the Universal 2 CLI tarball for the swiftpkg formula
  • checksum all four immutable release artifacts
  • dispatch exact CLI and app URLs and SHA-256 values to codecarton/homebrew-tap
  • remove the unsigned tag workflow so only the trusted signing path can create releases
  • document the new artifact names, requirements, receipts, and release flow

The official tap now renders and validates both Formula/swiftpkg.rb and
Casks/swiftpkgr.rb in one automated update PR.

Relates to #3 once the signed 0.3.1 release is published and its generated tap PR
is verified and merged.
Closes #17

Release artifacts

  • swiftpkg-<version>-combined.pkg
  • swiftpkg-<version>-cli.pkg
  • Swiftpkgr-<version>.zip
  • swiftpkg-<version>-universal.tar.gz
  • SHA256SUMS

Safety

Only the trusted local signing workflow publishes releases or dispatches
Homebrew updates; no tag-triggered unsigned workflow remains. The publisher
validates signatures, notarization, stapling, package payload separation,
archived app version, and immutable checksums before dispatch.

Validation

  • swift test
  • ./scripts/verify-loop.sh
  • sh -n scripts/publish-xcode-release.sh
  • unsigned Release builds for swiftpkg and Swiftpkgr
  • unsigned combined/CLI installer template build and payload validation
  • Homebrew renderer tests: 3 runs, 17 assertions
  • brew style for generated formula and cask
  • brew audit --strict for generated formula and cask
  • git diff --check

The final signed --build and Homebrew install checks require the trusted
release credentials and published 0.3.1 assets, so they remain release-time
acceptance checks.

Summary by CodeRabbit

  • New Features

    • Added separate combined and CLI-only macOS installers.
    • Added signed, notarized, and validated release artifacts, including app archives, Homebrew packages, and checksums.
    • Added automatic Homebrew tap updates after publishing releases.
  • Bug Fixes

    • Improved build activity display so progress status remains clearly visible.
  • Documentation

    • Updated installation, verification, publishing, and uninstallation guidance.
  • Release

    • Updated the application version to 0.3.1.

@coderabbitai

coderabbitai Bot commented Jul 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The release process now produces separate combined and CLI installers, app and tarball artifacts, validates signed outputs, creates immutable GitHub Releases, and dispatches Homebrew metadata. Version 0.3.1 metadata, installer templates, documentation, and build-status presentation were updated.

Changes

Release distribution

Layer / File(s) Summary
Release artifacts and version contracts
VERSION, swiftpkg/Version.swift, swiftpkg.xcodeproj/project.pbxproj, release/Swiftpkg*/*
Version metadata is updated to 0.3.1, and combined and CLI installer templates and project documentation are added or revised.
Artifact build and validation
scripts/publish-xcode-release.sh, release/SwiftpkgInstaller/README.md
The release script builds and validates combined and CLI packages, notarizes and staples the app, creates the universal tarball, and generates checksums.
Immutable release publishing
scripts/publish-xcode-release.sh, README.md
Publishing now rejects existing releases, creates a fresh GitHub Release, and dispatches artifact URLs and checksums to the Homebrew tap. README installation and maintainer-release instructions reflect the new artifacts and workflow.
Build status presentation
Swiftpkgr/Screens/BuildView.swift
The running build view separates the progress indicator from the displayed status message.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related issues

Possibly related PRs

  • codecarton/swiftpkg#5 — Both changes modify the release workflow and publishing script, including GitHub Release creation and unsigned fallback handling.

Suggested labels: enhancement

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The BuildView progress/status UI tweak is unrelated to the release artifact and Homebrew distribution work. Move the BuildView UI change to a separate PR unless it is required for the release flow.
Linked Issues check ❓ Inconclusive The main release and dispatch changes align with #3, but the Homebrew tap formula/workflow and verified PR are not shown here. Provide the codecarton/homebrew-tap formula and workflow changes, or evidence of the generated validated PR, to confirm end-to-end compliance.
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: split release artifacts plus Homebrew distribution support.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/homebrew

Comment @coderabbitai help to get the list of available commands.

@jordancalhoun jordancalhoun changed the title Add signed Homebrew release distribution Add split release artifacts and Homebrew packages Jul 18, 2026
@jordancalhoun
jordancalhoun marked this pull request as ready for review July 18, 2026 14:12
@jordancalhoun
jordancalhoun merged commit 972e5f0 into main Jul 18, 2026
1 of 2 checks passed
@jordancalhoun jordancalhoun added this to the Major Release: 1.0.0 milestone Jul 18, 2026
@jordancalhoun jordancalhoun added the enhancement New feature or request label Jul 18, 2026
@jordancalhoun
jordancalhoun deleted the feature/homebrew branch July 18, 2026 14:14

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@README.md`:
- Around line 167-178: Update the README release workflow description to state
that it creates a new immutable GitHub Release, removing the claim that it
creates or updates an existing release. Keep the surrounding publishing and
verification details unchanged.
- Around line 19-48: Add Homebrew lifecycle documentation to the README
installation section, covering tap setup and verified commands for installing,
upgrading, and uninstalling both the CLI formula and macOS app cask. Clearly
identify which Homebrew artifact each command manages, while preserving the
existing signed package and ZIP installation guidance.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e61c6bcb-cdcf-452c-a776-bcb7a2d91646

📥 Commits

Reviewing files that changed from the base of the PR and between 4de4310 and 783eccb.

📒 Files selected for processing (13)
  • .github/workflows/release.yml
  • README.md
  • Swiftpkgr/Screens/BuildView.swift
  • VERSION
  • release/SwiftpkgCLIInstaller/.gitignore
  • release/SwiftpkgCLIInstaller/README.md
  • release/SwiftpkgCLIInstaller/build-info.plist
  • release/SwiftpkgCLIInstaller/payload/.gitkeep
  • release/SwiftpkgInstaller/README.md
  • release/SwiftpkgInstaller/build-info.plist
  • scripts/publish-xcode-release.sh
  • swiftpkg.xcodeproj/project.pbxproj
  • swiftpkg/Version.swift
💤 Files with no reviewable changes (1)
  • .github/workflows/release.yml

Comment thread README.md
Comment on lines +19 to +48
Download `SHA256SUMS` and the appropriate signed, notarized artifact from the
matching GitHub Release:

Verify the download before installation:
- `swiftpkg-<version>-combined.pkg` installs both the CLI and Swiftpkgr and
requires macOS 15 or later.
- `swiftpkg-<version>-cli.pkg` installs only the CLI and requires macOS 13 or
later.
- `Swiftpkgr-<version>.zip` contains only the macOS 15+ app.

Verify a package download before installation:

```sh
shasum -a 256 -c SHA256SUMS
pkgutil --check-signature swiftpkg-<version>-universal.pkg
xcrun stapler validate swiftpkg-<version>-universal.pkg
sudo installer -pkg swiftpkg-<version>-universal.pkg -target /
grep ' swiftpkg-<version>-combined.pkg$' SHA256SUMS | shasum -a 256 -c -
pkgutil --check-signature swiftpkg-<version>-combined.pkg
xcrun stapler validate swiftpkg-<version>-combined.pkg
sudo installer -pkg swiftpkg-<version>-combined.pkg -target /
swiftpkg --version
```

The installer places the executable at `/usr/local/bin/swiftpkg` and the app at
`/Applications/Swiftpkgr.app`. Deploy that same installer through Munki, Jamf
Pro, or another management system; do not repackage its contents. Subsequent
releases replace the CLI and atomically upgrade the app bundle.
The combined installer places the executable at `/usr/local/bin/swiftpkg` and
the app at `/Applications/Swiftpkgr.app`. Deploy that artifact through Munki,
Jamf Pro, or another management system; do not repackage its contents. Use the
CLI package when managed Macs do not need the app. The ZIP can be expanded and
`Swiftpkgr.app` moved to `/Applications` for an app-only installation.

To uninstall, remove `/usr/local/bin/swiftpkg` and
`/Applications/Swiftpkgr.app`, then optionally forget the
`com.codecarton.swiftpkg.installer` receipt after confirming it is not needed
for inventory.
`com.codecarton.swiftpkg.installer` or
`com.codecarton.swiftpkg.cli.installer` receipt after confirming it is not
needed for inventory.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Document the Homebrew lifecycle.

This installation section omits Homebrew install, upgrade, and uninstall instructions for the new formula and cask. Add the verified tap commands and clarify which artifact each command manages. As per PR objectives, “The README must document Homebrew installation, upgrades, and uninstallation.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` around lines 19 - 48, Add Homebrew lifecycle documentation to the
README installation section, covering tap setup and verified commands for
installing, upgrading, and uninstalling both the CLI formula and macOS app cask.
Clearly identify which Homebrew artifact each command manages, while preserving
the existing signed package and ZIP installation guidance.

Comment thread README.md
Comment on lines +167 to +178
CLI and app products from Xcode, signs and notarizes them, and builds the
combined and CLI-only installers with the `swiftpkg` in `PATH`. It writes both
packages, the stapled app ZIP, the Homebrew CLI tarball, and `SHA256SUMS` to
`dist/`, pushes `main` and the explicit `v<version>` tag, and creates or updates
the GitHub Release. Once those signed assets are published, it dispatches the
immutable CLI and app URLs and checksums to `codecarton/homebrew-tap`, where
automation opens one tested formula-and-cask update pull request. The dispatch
token should be limited to that tap repository.

Only the trusted signing workflow creates the immutable GitHub Release. See
[VERIFICATION.md](VERIFICATION.md), [CONTRIBUTING.md](CONTRIBUTING.md), and
[SECURITY.md](SECURITY.md) for project processes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Describe release creation as create-only.

Line 170 says the workflow “creates or updates” a GitHub Release, but scripts/publish-xcode-release.sh fails when one already exists and always calls gh release create. State that it creates a new immutable release.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@README.md` around lines 167 - 178, Update the README release workflow
description to state that it creates a new immutable GitHub Release, removing
the claim that it creates or updates an existing release. Keep the surrounding
publishing and verification details unchanged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release signed and notarized standalone CLI, app, and combined artifacts

1 participant