mirror of
https://github.com/max-sixty/worktrunk.git
synced 2026-09-14 20:00:38 +08:00
codex/remove-codex-cloud-specific-tests
36 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
683bc9b91b |
docs(ci): record that the release/signing environments admit any tag (#3775)
The `release` and `signing` deployment branch policies were pinned to `v*` tags; they now admit any tag, and this records that. The "Tag operations" ruleset covers `~ALL` tags, so the `v*` pattern carried no part of the gate — tend's `_tags_admin_gated` credits a tag entry on that ruleset alone and never reads the pattern. What the pattern did do was duplicate `release.yaml`'s own tag filter, which is broader: `**[0-9]+.[0-9]+.[0-9]+*` matches an unprefixed `1.2.3`, which a `v*` policy would then refuse. A release cut under that name would have stopped at `build-local-artifacts` — it names `signing` and waits only on `plan`, so the refusal lands before an artifact is built, not at a publish job. Dropping the pattern removes the only place the two could drift. This also brings the repo onto the shape install-tend's §3 recipe documents (`-f name='*' -f type=tag`), which worktrunk had deviated from. `uvx tend check` still reports 8/8. Also updates a stale `v*` reference in the `signing` job's comment in `release.yaml`. > _This was written by Claude Code on behalf of max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
59c7320a78 |
ci: read TEND_BOT_TOKEN from an environment in every job (#3748)
Closes worktrunk's half of the `tend` environment migration (tend's `TODO.md`, "Finish moving the operational secrets into the `tend` environment", item 2). The environment is a secret scope, not a deploy target: its deployment branch policy is what stops a workflow pushed to a feature branch from reading the bot's PAT. That gate closes only when the repo-level copy of the secret is gone, since a job naming an environment still reads repo-level secrets. worktrunk kept one because these hand-maintained workflows read `TEND_BOT_TOKEN` outside tend's generated set. ## What changed | Job | Environment | Why that one | |---|---|---| | `benchmarks.yaml` `append-gist` (new) | `tend` | `schedule`-gated, so it runs on `main` | | `benchmarks.yaml` `create-issue-on-benchmark-failure` | `tend` | already `schedule`-gated | | `nightly.yaml` `create-issue-on-nightly-failure` | `tend` | already `schedule`-gated | | `release.yaml` `publish-winget` | `release` | runs on a `v*` tag push | | `release.yaml` `publish-homebrew` | `release` | runs on a `v*` tag push | Every job reading `TEND_BOT_TOKEN` now names an environment, so deleting the repo-level copy breaks nothing. ### The gist append moved into its own job The `benchmarks` job has no `if` gate, so putting `tend` on it would refuse a `workflow_dispatch` against a non-`main` ref — on-demand runs against a chosen branch are what that trigger is documented for. A job GitHub skips never requests its environment, so moving the append into a `schedule`-gated `append-gist` job keeps the policy off the dispatch path entirely. It reads `target/criterion` back from the artifact the `benchmarks` job already uploads. `create-issue-on-benchmark-failure` now `needs` both jobs, so a failed append still files an issue — previously it failed the `benchmarks` job directly. ### Why the release jobs get `release`, not `tend` A tag push is not bot-steerable and tag creation and update are already restricted to admins by the "Tag operations" ruleset, so a tag policy is a real boundary. The tag entry cannot go on `tend`: `tend check`'s `check_environment` pins that policy to exactly the protected branches and its `--fix` deletes anything else. `release` already exists with a `v*` tag policy and already holds `AUR_SSH_PRIVATE_KEY`, so no new environment and no new credential — `TEND_BOT_TOKEN` is seeded into it as a second copy. ### `deployment: false` Jobs naming `tend` use the mapping form. GitHub files a deployment record for every job that names an environment, against whatever ref the run belongs to; under `pull_request_target` that is the PR's own head, which is why PR timelines grew a "worktrunk-bot deployed to tend" line on every push. `deployment: false` drops the record and keeps the gate. The release jobs keep their records, which land in no PR timeline. ## Follow-up: one step, after merge `TEND_BOT_TOKEN` is **already seeded into the `release` environment** (read from the local `worktrunk-bot` gh config dir at `~/.config/gh-bots/worktrunk-bot`, so no new credential was minted and nothing was pasted). Verified: the token resolves to `worktrunk-bot` and has push on both `max-sixty/winget-pkgs` and `max-sixty/homebrew-worktrunk`. That leaves one step, and it must come **after** this PR merges: ``` gh secret delete TEND_BOT_TOKEN --repo max-sixty/worktrunk ``` Not before. On `main` today the gist append, both `create-issue-on-*-failure` jobs, and the two publish jobs still read the token with no environment named, so deleting the repo-level copy first would break the next benchmarks cron (03:47 UTC daily). Merging this PR is what makes the deletion safe. ## What this does not fix - `repo-secret-allowlist` still fails on `CLAUDE_CODE_OAUTH_TOKEN`, also at repo level. It cannot be read back either; separate item. - `environment-deployments` still fails on the generated `tend-*.yaml`, which pin tend 0.1.13 and carry the bare `environment: tend`. Those are regenerated by the published tend, and a regen also carries an unrelated `gh api --paginate` fix in `tend-mention.yaml`, so it belongs in its own PR. ## Verification - The `append-gist` script was run end-to-end against a real `benchmark-results-*` artifact from run 30976221483. It emits 40 rows whose `bench` names match the live gist's existing rows exactly, confirming the artifact round-trip preserves paths relative to `target/criterion`. - That a skipped `if` short-circuits the environment gate is confirmed by run 31066000517: `publish-cargo`, which names `environment: release`, completed as *skipped* on a `pull_request` from a non-tag ref rather than failing on the policy. - `actionlint` reports the same eight pre-existing shellcheck notes as `main`; no new findings. `pre-commit` passes. > _This was written by Claude Code on behalf of max-sixty_ |
||
|
|
aa988b37bb |
ci(release): scope SIGNPATH_API_TOKEN to a dedicated signing environment (#3704)
`SIGNPATH_API_TOKEN` sits at repo level, where every workflow the repo
runs can read it. It is referenced once, by the "Submit SignPath signing
request" step in `build-local-artifacts`. This joins that job to a new
`signing` environment so the token can be held there instead.
The environment already exists, with a `v*` tag policy and no reviewer
rule. It holds no secret yet, and this PR is safe to merge before it
does: an environment secret *overrides* a repository one of the same
name rather than displacing access to it, so until `signing` holds a
token the job keeps reading the repo-level copy and signing behaves
exactly as it does today.
Two steps remain, and both need the token value, which is write-only and
so has to be set by hand — or re-issued from the SignPath console, which
rotates it at the same time:
```
gh secret set SIGNPATH_API_TOKEN --repo max-sixty/worktrunk --env signing
```
```
gh secret delete SIGNPATH_API_TOKEN --repo max-sixty/worktrunk
```
The delete is what clears the drift, and it is the one step with an
ordering constraint: run it after the environment secret exists, or the
next release signs with an empty token.
## Why a new environment rather than the existing `release`
Reusing `release` looks cheaper, and the usual objection to it turns out
to be false: `release` has no reviewer rule, so it would not have pulled
an approval gate into the build phase. Its only protection rule is a
`v*` tag policy, which is why `publish-cargo` and `publish-aur` deploy
to it unattended today.
The real problem is the other direction. A job that joins an environment
can read *every* secret in it, and `release` holds
`AUR_SSH_PRIVATE_KEY`. Putting `build-local-artifacts` there would give
the build phase the AUR deploy key, so the change would trade one
over-broad grant for another rather than removing one. `signing` holds
the single token its single consumer needs.
Allowlisting the secret in `.config/tend.yaml` was the third option. It
records "intentionally repo-wide", which is the wrong posture for a
credential that becomes a real code-signing key once the SignPath OSS
application clears. It is a self-signed test certificate today, which is
the argument for moving it now rather than after.
<details><summary>Verification</summary>
`.github/CLAUDE.md` claimed the `release` environment required
"deployment approval from `@max-sixty`". That was the source of the
approval-gate objection, and it was wrong:
```
$ gh api repos/max-sixty/worktrunk/environments/release
"protection_rules": [{"id": 48355233, "type": "branch_policy"}]
$ gh api repos/max-sixty/worktrunk/environments/release/deployment-branch-policies
{"branch_policies": [{"name": "v*", "type": "tag"}]}
```
No `required_reviewers` rule. The v0.71.0 deployment confirms it
behaviorally — `waiting` to `queued` in one second, with no approval in
between:
```
$ gh api repos/max-sixty/worktrunk/deployments/5682057674/statuses
success 2026-07-30T20:46:46Z
in_progress 2026-07-30T20:45:00Z
queued 2026-07-30T20:44:57Z
waiting 2026-07-30T20:44:56Z
```
That doc line is rewritten here, into a table of which environment holds
what and which job reads it.
Three other things worth confirming before touching a dist-generated
file:
- **Hand edits survive.** `dist-workspace.toml` sets `allow-dirty =
["ci"]`, and no job anywhere runs `dist generate --check`. The custom
`publish-cargo`, `publish-winget`, and `publish-aur` jobs already only
exist because of this.
- **The environment doesn't serialize the matrix.** `publish-cargo` and
`publish-aur` both target `release` and ran concurrently in the v0.71.0
release (started `20:44:58` and `20:44:59`), so the five matrix legs
won't queue behind each other.
- **tend only scans repo-level secrets.** `AUR_SSH_PRIVATE_KEY` and
`WINGET_TOKEN` sit in the `release` environment and `tend check` passes
them without complaint, so moving `SIGNPATH_API_TOKEN` to an environment
is what clears the check.
</details>
## Risk
Low. The repo-level token remains readable until it is deleted, so
signing is unaffected by the merge. Even with no token reachable at all,
the signing step is `continue-on-error: true` while the certificate is a
test one, so it would fail without blocking the crates.io, Homebrew,
winget, or AUR publishes — the one step that is deliberately not
`continue-on-error` just recomputes a checksum over whatever zip is in
place.
One coupling is now load-bearing and is noted in the workflow: the `v*`
tag policy means setting `pr-run-mode = "upload"` in
`dist-workspace.toml` would make GitHub reject this job on a PR ref.
Today `pr-run-mode` defaults to `plan`, so `build-local-artifacts` is
skipped on pull requests entirely — which also means this PR's own CI
does not exercise the change. The first real exercise is the next
release tag.
Ref #3572 — the issue closes once the repo-level secret is deleted.
> _This was written by Claude Code on behalf of max-sixty_
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|
|
f1f1b50d85 |
docs(release): trim the signing archaeology now the path is proven (#3593)
Follow-up to #3590, now that v0.69.2 has shipped a signed Windows binary — verified against the published asset rather than the logs: ``` git-wt.exe: certificate table 8480 bytes wt.exe: certificate table 8472 bytes c4343fb5…1a43 *worktrunk-x86_64-pc-windows-msvc.zip (published .sha256 matches) ``` Comments only; no behavior change. The signing comments were written while the mechanism was still being guessed at, so they carried the failed attempts — a ten-line account of the zip-of-a-zip failure, a six-line account of the `…zip.zip` collision. The path is proven and the workflow now verifies itself, so what a reader needs is the current mechanism. Trimmed to that. One thing added rather than removed. `Recompute checksum` sits between two `continue-on-error` steps and looks like it should fold into the replace step above it. It must not: the signing steps are tolerant because publishing can't depend on a self-signed test certificate, while a checksum that doesn't match the shipped zip has to fail the release. That asymmetry is invisible in the YAML, so it's now stated — the next person to simplify this shouldn't have to rediscover it. > _This was written by Claude Code on behalf of max_ |
||
|
|
6b29c2802b |
Release v0.69.2 (#3590)
Cuts v0.69.2, and fixes the Windows code-signing path it depends on. ## The signing fix v0.69.1 shipped an unsigned `wt.exe` under a green run and a **Completed** SignPath signing request. `archive: false` (#3566) had already made the GitHub artifact name `worktrunk-x86_64-pc-windows-msvc.zip`, and SignPath names its download after the artifact — so with `output-artifact-directory: target/distrib` the signed zip landed at `worktrunk-x86_64-pc-windows-msvc.zip.zip`, beside the untouched unsigned build. The checksum step and the release upload both kept reading the original. Confirmed by parsing the published asset's PE certificate table: `size=0`. The download now goes to a scratch directory and whatever single file lands there replaces the built zip, so SignPath's naming isn't load-bearing. ## Verification, because this failure is invisible Signing is `continue-on-error` by design (self-signed test certificate pending SignPath's OSS review), so nothing in the logs distinguishes "signed" from "silently unsigned" — which is how it slipped through twice, two different ways. `.github/verify-windows-signature.py` reads the zip's PE certificate tables directly, and runs at two points with distinct jobs: - **before the overwrite** — an unsigned release is tolerable while the certificate is a test one; a corrupt one never is, so the replacement has to verify before it can clobber a good build. - **after** — reports what the release actually ships, which is the question the logs never answered. ## Rehearsed before landing The signing path only runs on a tag, so each question about it used to cost a release. This chain was instead run on a Windows runner against the already-published v0.69.1 zip (identical bytes, no build): ``` saved to …\target\signpath\worktrunk-x86_64-pc-windows-msvc.zip.zip git-wt.exe: certificate table 8480 bytes wt.exe: certificate table 8472 bytes → mv → target/distrib/worktrunk-x86_64-pc-windows-msvc.zip target/distrib/worktrunk-x86_64-pc-windows-msvc.zip: all 2 executables signed worktrunk-x86_64-pc-windows-msvc.zip: OK (checksum matches) ``` That also settled the open question behind #3556: SignPath returns the signed zip itself, not a wrapper, so `skip-decompress: true` is correct — the extract mode does explode it into loose files. ## Release contents `wt remove`'s fsmonitor sweep (#3581), the troubleshooting doc trim, and this fix. The two refactors in range (#3582, #3584) are behavior-preserving and omitted per convention. Local gate green (4547 passed). Changelog entries verified against the diffs by subagent; two claims corrected (the doc entry's rationale, and an overclaim attributing v0.69.0's unsigned binary to this bug rather than the separate upload failure #3566 fixed). Data-loss surface reviewed across the cumulative diff. > _This was written by Claude Code on behalf of max_ |
||
|
|
7b741d0791 |
fix(release): stop double-zipping the SignPath upload artifact (#3566)
## Summary - `actions/upload-artifact` wraps every upload in its own GitHub storage zip unless `archive: false`. The uploaded file here is already a zip (`worktrunk-x86_64-pc-windows-msvc.zip`), so the default produced a zip-of-a-zip — SignPath treated the outer storage wrapper as "the artifact" and the configured `<pe-file path="wt.exe">` never matched anything inside it. - Root-caused this against the real v0.69.0 release run: the SignPath dashboard shows the failed request's unsigned artifact as `unsigned-windows-zip.zip` (16.8MB, matching GitHub's storage-wrapper name, not the real filename) with error `Expected path to match exactly 1 item, but found 0` for `wt.exe`. - `archive: false` uploads the file as-is (single-file only, which is what we have), so SignPath receives the real zip directly, one level shallower — matching the artifact configuration as originally written. - Also fixes the v0.69.0 CHANGELOG's SignPath entry, which read "Signed with a test certificate" — overclaiming, since the actual signing attempt on that release failed. Reworded to describe the pipeline's intent rather than a specific run's result. v0.69.0 shipped with an unsigned Windows binary as a result (signing failure was masked by the intentional `continue-on-error`, so the release itself succeeded — this is exactly the non-blocking behavior that was designed in). This fix should make the next release's signing attempt succeed for real. ## Test plan - [x] `actionlint .github/workflows/release.yaml` — no new warnings - [x] Root cause confirmed directly against the SignPath dashboard's error details and artifact tab for the failed v0.69.0 signing request - [x] Verified `archive: false` semantics against `actions/upload-artifact@v7`'s own `action.yml` (single-file upload, uploaded as-is) > _This was written by Claude Code on behalf of Max_ |
||
|
|
481125801f |
ci: publish to crates.io via trusted publishing (#3564)
## What `publish-cargo` now mints its crates.io credential per run through `rust-lang/crates-io-auth-action` (GitHub Actions OIDC) instead of reading the `CARGO_REGISTRY_TOKEN` environment secret. The job gains `id-token: write` for the OIDC exchange and `contents: read` for checkout, narrowing it from the workflow-level `contents: write`. The token lives for about 30 minutes and the action's post step revokes it, so no long-lived publish credential exists anywhere. ## Why The stored token expires on a schedule, and each expiry is a silent trap: nothing breaks until the next release tag, which is exactly when you don't want to discover it. ## Prerequisite, already in place A Trusted Publisher is configured for `worktrunk` on crates.io — repository `max-sixty/worktrunk`, workflow `release.yaml`, environment `release`. It had to land before this merge, since otherwise `publish-cargo` would fail at the auth step on the next release tag. `CARGO_REGISTRY_TOKEN` can be deleted from the `release` environment once a release has gone out this way. `AUR_SSH_PRIVATE_KEY` stays. > _This was written by Claude Code on behalf of max_ |
||
|
|
8f55d15301 |
fix(release): preserve signed Windows zip filename, match checksum format (#3556)
## Summary - The SignPath action's `skip-decompress` defaults to `false`, so it would have extracted the returned zip's contents as loose files into `target/distrib/` instead of saving back a signed `worktrunk-x86_64-pc-windows-msvc.zip`. The checksum step would have silently hashed the still-unsigned zip, and the release would have shipped unsigned Windows binaries with no CI failure to flag it. - `sha256sum` without `-b` omits the `*` binary-mode marker; cargo-dist's own checksums use `<hash> *<filename>` (confirmed against a real release asset). Added `-b` to match. Confirmed via `gh run view` on #3553's own CI run that `build-local-artifacts` is skipped on PRs in this repo, so this code path has never actually executed — this is the first real fix before it runs for real on a tagged release. ## Test plan - [x] `actionlint .github/workflows/release.yaml` — no new warnings (same pre-existing shellcheck style notes as before) - [x] Verified `skip-decompress` behavior against the action's own `action.yml` input spec - [x] Verified checksum format against a real downloaded release asset (`v0.68.0`) > _This was written by Claude Code on behalf of Max_ |
||
|
|
5f8c301dec |
feat(release): sign Windows binaries via SignPath (#3553)
## Summary - Signs the Windows release zip (`wt.exe` + `git-wt.exe`) via [SignPath](https://signpath.io)'s free OSS code-signing program, using the `test-signing` policy (self-signed test certificate) while the project's Foundation-program application is under review. - Non-blocking (`continue-on-error`) so a signing hiccup can't take down crates.io/homebrew/winget/AUR publishing. - Recomputes the `.sha256` checksum after signing, since the signed zip's bytes differ from the unsigned one. - Uses a dedicated low-privilege `CI builds` SignPath identity (submitter-only), not an admin account. ## Test plan - [x] `actionlint` clean (only pre-existing shellcheck style warnings elsewhere in the file) - [x] Artifact configuration (zip containing `wt.exe` + `git-wt.exe`) validated against SignPath's own XML parser and against the real file layout inside a downloaded `v0.68.0` Windows release zip - [ ] First real Windows build after merge will be the first live signing round-trip through GitHub Actions — watch that release's CI run > _This was written by Claude Code on behalf of Max_ --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> |
||
|
|
013d1cc221 |
chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.3 to 4.2.0 (#3472)
Bumps [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) from 4.1.3 to 4.2.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's releases</a>.</em></p> <blockquote> <h2>v4.2.0</h2> <p>Add a feature to sync AUR repo (<a href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/52">KSXGitHub/github-actions-deploy-aur#52</a>).</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/084b0d9b15415bf9cdb65d44dad1efe37a354050"><code>084b0d9</code></a> style: consistency (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/55">#55</a>)</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/9e2f21095c586521806151200746082d8e02bb90"><code>9e2f210</code></a> fix: force-add <code>PKGBUILD</code> and <code>.SRCINFO</code> in the asset_dir/assets path (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/53">#53</a>)</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/7acb32fe8c43848121eee16dd39d8294ec2bf25b"><code>7acb32f</code></a> feat: full asset sync (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/52">#52</a>)</li> <li>See full diff in <a href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.3...v4.2.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9e8d4612c8 |
chore: bump actions/checkout from 6 to 7 (#3131)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/releases">actions/checkout's releases</a>.</em></p> <blockquote> <h2>v7.0.0</h2> <h2>What's Changed</h2> <ul> <li>block checking out fork pr for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> <li>getting ready for checkout v7 release by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li> <li>update error wording by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p> <h2>v6.0.3</h2> <h2>What's Changed</h2> <ul> <li>Update changelog by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>Update changelog for v6.0.3 by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/yaananth"><code>@yaananth</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p> <h2>v6.0.2</h2> <h2>What's Changed</h2> <ul> <li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p> <h2>v6.0.1</h2> <h2>What's Changed</h2> <ul> <li>Update all references from v5 and v4 to v6 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> <li>Clarify v6 README by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v7.0.0</h2> <ul> <li>Block checking out fork PR for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> </ul> <h2>v6.0.3</h2> <ul> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <h2>v6.0.2</h2> <ul> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <h2>v6.0.1</h2> <ul> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> </ul> <h2>v6.0.0</h2> <ul> <li>Persist creds to a separate file by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li> <li>Update README to include Node.js 24 support details and requirements by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li> </ul> <h2>v5.0.1</h2> <ul> <li>Port v6 cleanup to v5 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li> </ul> <h2>v5.0.0</h2> <ul> <li>Update actions checkout to use node 24 by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li> </ul> <h2>v4.3.1</h2> <ul> <li>Port v6 cleanup to v4 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li> </ul> <h2>v4.3.0</h2> <ul> <li>docs: update README.md by <a href="https://github.com/motss"><code>@motss</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li> <li>Add internal repos for checking out multiple repositories by <a href="https://github.com/mouismail"><code>@mouismail</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li> <li>Documentation update - add recommended permissions to Readme by <a href="https://github.com/benwells"><code>@benwells</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li> <li>Adjust positioning of user email note and permissions heading by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li> <li>Update README.md by <a href="https://github.com/nebuk89"><code>@nebuk89</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li> <li>Update CODEOWNERS for actions by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li> <li>Update package dependencies by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li> </ul> <h2>v4.2.2</h2> <ul> <li><code>url-helper.ts</code> now leverages well-known environment variables by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li> <li>Expand unit test coverage for <code>isGhes</code> by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li> </ul> <h2>v4.2.1</h2> <ul> <li>Check out other refs/* by commit if provided, fall back to ref by <a href="https://github.com/orhantoy"><code>@orhantoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a> update error wording (<a href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li> <li><a href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a> getting ready for checkout v7 release (<a href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a> Bump the minor-npm-dependencies group across 1 directory with 3 updates (<a href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li> <li><a href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a> upgrade module to esm and update dependencies (<a href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li> <li><a href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a> Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid (<a href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li> <li><a href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a> Bump js-yaml from 4.1.0 to 4.2.0 (<a href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li> <li><a href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a> Bump flatted from 3.3.1 to 3.4.2 (<a href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li> <li><a href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a> Bump actions/publish-immutable-action (<a href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a> block checking out fork pr for pull_request_target and workflow_run (<a href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li> <li>See full diff in <a href="https://github.com/actions/checkout/compare/v6...v7">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
fbe9aea898 |
ci: rename WORKTRUNK_BOT_TOKEN → TEND_BOT_TOKEN in non-tend workflows (#2781)
Per [@max-sixty's request on #2776](https://github.com/max-sixty/worktrunk/pull/2776#issuecomment-4472516748): finish the `WORKTRUNK_BOT_TOKEN` → `TEND_BOT_TOKEN` rename in the non-tend workflows that #2776 left behind. ## Changes - `.github/workflows/nightly.yaml` — gist append (`GITHUB_TOKEN` on the `💾 Append results to gist` step) and the failure-issue creator (`JasonEtco/create-an-issue`). Comments updated to match. - `.github/workflows/release.yaml` — `GH_TOKEN` for the winget-pkgs fork sync, the `winget-releaser@v2` token, and the homebrew-worktrunk checkout token. - `.github/CLAUDE.md` — Tokens table now lists `TEND_BOT_TOKEN`. ## Why this is safe Both secrets currently point at the same PAT (per #2773), so this is a name-only swap — no permission or scope change. The tend-managed workflows already migrated in #2776; this PR catches the ones tend's regen doesn't touch. After merge, the obsolete `WORKTRUNK_BOT_TOKEN` (and `BOT_TOKEN`) secret can be deleted from repo settings — tracked in #2775. ## Test plan - [ ] CI green on this PR - [ ] Next scheduled `nightly` run successfully appends to the benchmark gist - [ ] Next release publish reaches winget + homebrew 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
99d9307b11 |
chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.2 to 4.1.3 (#2312)
Bumps [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) from 4.1.2 to 4.1.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's releases</a>.</em></p> <blockquote> <h2>v4.1.3</h2> <p>There is a bug in <code>runuser</code> that converts all <code>-c</code> (even after <code>--</code>) into <code>--command</code> which <code>bash</code> doesn't recognize. This release removes the <code>-c</code> flag entirely, bash would execute <code>/build.sh</code> as if it's a file. Hopefully, the behavior preserves. If not, maybe just switch to <code>su</code> or <code>sudo</code>.</p> <p>Relevant PR: <a href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51">KSXGitHub/github-actions-deploy-aur#51</a>.</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7"><code>da03e16</code></a> fix: <code>bash: --command: invalid option</code> (<a href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51">#51</a>)</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1"><code>3b403c7</code></a> docs(readme): use the GitHub's note syntax</li> <li><a href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2"><code>e17cd79</code></a> docs(readme): remove patreon</li> <li>See full diff in <a href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.2...v4.1.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
da19f329e5 |
fix: bump AUR deploy action to v4.1.2 (#1909)
Arch Linux updated util-linux with stricter `runuser` argument parsing in su-compatible mode. The v4.1.1 entrypoint ran `runuser builder --command 'bash -l -c /build.sh'`, but with the username before `--command`, the new `runuser` passes `--command` as a shell argument to bash — producing `bash: --command: invalid option`. This broke the v0.34.1 AUR publish. v4.1.2 ([KSXGitHub/github-actions-deploy-aur#49](https://github.com/KSXGitHub/github-actions-deploy-aur/pull/49), released 2026-04-03) switches to `runuser -u builder -- bash -l -c /build.sh`. > _This was written by Claude Code on behalf of @max-sixty_ Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
8a0404de49 |
ci: remove dist binary caching from release workflow (#1299)
## Summary - Remove the `cargo-dist-cache` artifact pattern that shared the `dist` binary between release jobs - Install `dist` fresh via the official installer script in `build-global-artifacts` and `host` jobs (same as `plan` and `build-local-artifacts` already do) - Ensures a poisoned cache cannot affect release artifacts Closes #1298 ## Test plan - [ ] Release workflow YAML is valid (CI will run the `plan` job on this PR) - [ ] Each job that needs `dist` installs it independently 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|
|
51c9e586bd | chore: bump actions/download-artifact from 7 to 8 (#1218) | ||
|
|
2a67c5e787 | chore: bump actions/upload-artifact from 6 to 7 (#1217) | ||
|
|
bd188aa7ef |
CI security model: rulesets, token consolidation, environment protection (#1118)
## Summary - Consolidate all Claude workflows to `WORKTRUNK_BOT_TOKEN` for consistent identity. The merge restriction (ruleset) is the security boundary, not token scoping. - Review workflow: `contents: read`, BOT_TOKEN for API calls, sticky comment - Mention workflow: add PR branch checkout for `pull_request_review_comment` events - Add `.github/CLAUDE.md` documenting the full security model: threat model, token strategy, branch protection, environment protection Infrastructure changes (via API, not in code): - Ruleset "Merge access" on `main`: "Restrict updates" rule, admin exempt bypass - GitHub Environment `release` with deployment protection (`v*` tags only) - Deleted `WORKTRUNK_REVIEW_TOKEN` from repo secrets - Moved `CARGO_REGISTRY_TOKEN` to `release` environment ## Test plan - [ ] Verify review workflow posts as `worktrunk-bot` (this PR triggers it) - [ ] Verify `@claude` mention works on issues and PR review comments - [ ] Verify admin can merge without bypass checkbox friction - [ ] Verify bot cannot merge PRs (ruleset blocks non-admin) > _This was written by Claude Code on behalf of @max-sixty_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
48c6b97385 |
docs(release): improve install instructions in release notes (#918)
- Replace tap formula (max-sixty/worktrunk/wt) with homebrew-core (worktrunk) - Add shell install suffix to all install commands - Add Cargo, Winget, and AUR install options Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
dfcbeaab01 |
chore(ci): pin runner versions and add weekly renovation workflow (#878)
* chore(ci): pin runner versions and add weekly renovation workflow Pin all GitHub Actions runners to specific versions instead of using -latest labels to avoid surprise breaking changes from migrations (like the recent Windows 2025 D: drive issue). Pinned versions: - ubuntu-24.04 (current ubuntu-latest) - macos-15 (current macos-latest) - windows-2022 (windows-2025 lacks D: drive, actions/runner-images#12677) Also adds claude-renovate.yaml workflow that runs weekly to check for: - Runner version updates - GitHub Actions version updates - Rust nightly version updates for cargo-udeps Co-Authored-By: Claude <noreply@anthropic.com> * Use stable job names for test matrix Use `test (linux)`, `test (macos)`, `test (windows)` instead of embedding version numbers in job names. This way branch protection rules don't need updating when runner versions change. Co-Authored-By: Claude <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
55e841e0b8 |
Add AUR publish workflow (#585)
* Add AUR publish workflow - Add PKGBUILD template in .github/aur/ - Add publish-aur job to release workflow using github-actions-deploy-aur - Uses updpkgsums to auto-calculate checksums from release assets Requires AUR_SSH_PRIVATE_KEY secret to be configured. Co-Authored-By: Claude <noreply@anthropic.com> * Update .github/aur/PKGBUILD Co-authored-by: Evan Sosenko <razorx@evansosenko.com> * Address AUR package review feedback - Remove git-wt binary (not needed for Arch users) - Add fish completions to standard location Co-Authored-By: Claude <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Evan Sosenko <razorx@evansosenko.com> |
||
|
|
2e5e9aefbd |
refactor(ci): use cargo-dist for Homebrew formula generation (#593)
* refactor(ci): use cargo-dist for Homebrew formula generation Replace manual sed-based formula updates with cargo-dist's built-in Homebrew publishing: - Add `homebrew` to installers in dist-workspace.toml - Configure tap and formula name - Replace publish-homebrew job to use the formula generated by cargo-dist - Add homepage to Cargo.toml (required by cargo-dist) This eliminates the fragile sed patterns that previously broke when updating SHA256 hashes, as cargo-dist now generates the complete formula with correct multi-arch support. Co-Authored-By: Claude <noreply@anthropic.com> * simplify: remove complex JSON parsing from publish-homebrew cargo-dist generates a single wt.rb - no need to parse PLAN JSON to find artifacts or handle multiple packages. Co-Authored-By: Claude <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
cb7a32f48a |
fix(ci): correct SHA256 hash updates in Homebrew formula (#591)
The previous sed commands used "0,/pattern/s//" to replace the "first
match", but after each replacement the new hash was still a valid 64-char
hex string, so subsequent seds kept matching and overwriting the same
line. This left the first sha256 with the Linux hash while the Intel and
Linux positions were never updated.
Fix by matching each URL pattern and updating the sha256 on the next line
using sed's {n;s/...} syntax, ensuring each hash is updated independently.
Co-authored-by: Claude <noreply@anthropic.com>
|
||
|
|
aeffd687fc |
ci: automate Homebrew formula updates in release workflow
Add publish-homebrew job that: - Clones homebrew-worktrunk using bot token - Fetches SHA256 hashes from release assets - Updates formula with sed - Commits and pushes Also updates release skill to reflect full automation. Co-Authored-By: Claude <noreply@anthropic.com> |
||
|
|
a1283dae16 |
ci: sync winget-pkgs fork before publishing
The winget publish job was failing because the fork of microsoft/winget-pkgs was thousands of commits behind upstream. Komac couldn't create a branch from such an outdated base. Add a step to sync the fork with upstream before publishing. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> |
||
|
|
d3f34b85ef |
Enable automatic winget package publishing (#241)
Uncomment and configure the publish-winget job to automatically submit PRs to winget-pkgs on new releases using vedantmgoyal9/winget-releaser. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
d884c6f962 |
chore: bump actions/download-artifact from 6 to 7 (#200)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 6 to 7. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/v6...v7) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
7ed748cf92 |
chore: bump actions/upload-artifact from 5 to 6 (#201)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/v5...v6) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4e63480fa2 |
Remove unnecessary --locked flags from CI
Cargo.lock is committed and updated by cargo check before commits. --locked adds overhead without providing value for this workflow. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> |
||
|
|
8af4cbbc77 |
Fix cargo publish to specify package explicitly
The workspace has dev-detach in default-members for cargo test builds. Specify --package worktrunk to avoid attempting to publish dev-detach. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> |
||
|
|
1590855c43 |
Disable winget publishing until initial package submission
The winget-releaser action requires the package to already exist in the winget-pkgs repository. Manual initial submission is required: https://github.com/microsoft/winget-pkgs/blob/master/CONTRIBUTING.md 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> |
||
|
|
079c9df3fb |
Add winget publish job to release workflow
Add a new publish-winget job that publishes releases to Windows Package Manager. This job runs after the plan and host jobs, uses the winget-releaser action to publish the release, and is added as a dependency for the announce job to ensure it completes before announcement. |
||
|
|
976ebce4c7 |
Remove unnecessary dtolnay/rust-toolchain from CI workflows (#115)
GitHub runners (ubuntu-latest, macos-latest, windows-latest) come with Rust stable pre-installed including rustfmt and clippy. The explicit toolchain installation step is unnecessary. This matches how prql handles Rust setup - they don't use dtolnay/rust-toolchain at all and rely on the pre-installed Rust. Removed from: - ci.yaml: test job and benchmarks job - claude.yaml: Claude Code action job - release.yaml: publish-cargo job 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
112b95a762 |
Add explicit workflow names and standardize to lowercase format
Workflow files now include explicit `name` fields at the top and use lowercase naming convention. This improves workflow visibility and consistency in GitHub Actions UI. |
||
|
|
28aaab33a5 |
Add workflow names for cleaner CI check display (#80)
GitHub shows file paths when workflows lack names. Adding `name: CI` and `name: Release` gives cleaner check names like "CI / test (macos-latest)" instead of ".github/workflows/ci.yaml / test (macos-latest)". 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
464647c29b |
ci: Standardize workflow file naming (#67)
* ci: Standardize workflow file naming - Rename all workflow files from .yml to .yaml for consistency - Remove workflow and job name: fields (use job IDs as display names) - Update references to renamed files in publish-docs and README badge 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * docs: Generate command reference from `help --md` - Replaces static command documentation in `docs/content/commands.md` with auto-generated content from `wt <command> --help-md`. - Moves advanced tips and patterns to a new `docs/content/tips-patterns.md` page. - Updates navigation weights and `wt select` documentation to reflect these changes. - Adds an integration test to ensure the generated documentation remains in sync with the CLI help output. --------- Co-authored-by: Claude <noreply@anthropic.com> |