Commit Graph

36 Commits

Author SHA1 Message Date
Maximilian Roos 683bc9b91b docs(ci): record that the release/signing environments admit any tag (#3775)
The `release` and `signing` deployment branch policies were pinned to
`v*` tags; they now admit any tag, and this records that.

The "Tag operations" ruleset covers `~ALL` tags, so the `v*` pattern
carried no part of the gate — tend's `_tags_admin_gated` credits a tag
entry on that ruleset alone and never reads the pattern. What the
pattern did do was duplicate `release.yaml`'s own tag filter, which is
broader: `**[0-9]+.[0-9]+.[0-9]+*` matches an unprefixed `1.2.3`, which
a `v*` policy would then refuse. A release cut under that name would
have stopped at `build-local-artifacts` — it names `signing` and waits
only on `plan`, so the refusal lands before an artifact is built, not at
a publish job. Dropping the pattern removes the only place the two could
drift.

This also brings the repo onto the shape install-tend's §3 recipe
documents (`-f name='*' -f type=tag`), which worktrunk had deviated
from. `uvx tend check` still reports 8/8.

Also updates a stale `v*` reference in the `signing` job's comment in
`release.yaml`.

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-08 13:06:19 -07:00
Maximilian Roos 59c7320a78 ci: read TEND_BOT_TOKEN from an environment in every job (#3748)
Closes worktrunk's half of the `tend` environment migration (tend's
`TODO.md`,
"Finish moving the operational secrets into the `tend` environment",
item 2).

The environment is a secret scope, not a deploy target: its deployment
branch
policy is what stops a workflow pushed to a feature branch from reading
the
bot's PAT. That gate closes only when the repo-level copy of the secret
is
gone, since a job naming an environment still reads repo-level secrets.
worktrunk kept one because these hand-maintained workflows read
`TEND_BOT_TOKEN` outside tend's generated set.

## What changed

| Job | Environment | Why that one |
|---|---|---|
| `benchmarks.yaml` `append-gist` (new) | `tend` | `schedule`-gated, so
it runs on `main` |
| `benchmarks.yaml` `create-issue-on-benchmark-failure` | `tend` |
already `schedule`-gated |
| `nightly.yaml` `create-issue-on-nightly-failure` | `tend` | already
`schedule`-gated |
| `release.yaml` `publish-winget` | `release` | runs on a `v*` tag push
|
| `release.yaml` `publish-homebrew` | `release` | runs on a `v*` tag
push |

Every job reading `TEND_BOT_TOKEN` now names an environment, so deleting
the
repo-level copy breaks nothing.

### The gist append moved into its own job

The `benchmarks` job has no `if` gate, so putting `tend` on it would
refuse a
`workflow_dispatch` against a non-`main` ref — on-demand runs against a
chosen
branch are what that trigger is documented for. A job GitHub skips never
requests its environment, so moving the append into a `schedule`-gated
`append-gist` job keeps the policy off the dispatch path entirely. It
reads
`target/criterion` back from the artifact the `benchmarks` job already
uploads.

`create-issue-on-benchmark-failure` now `needs` both jobs, so a failed
append
still files an issue — previously it failed the `benchmarks` job
directly.

### Why the release jobs get `release`, not `tend`

A tag push is not bot-steerable and tag creation and update are already
restricted to admins by the "Tag operations" ruleset, so a tag policy is
a
real boundary. The tag entry cannot go on `tend`: `tend check`'s
`check_environment` pins that policy to exactly the protected branches
and its
`--fix` deletes anything else. `release` already exists with a `v*` tag
policy
and already holds `AUR_SSH_PRIVATE_KEY`, so no new environment and no
new
credential — `TEND_BOT_TOKEN` is seeded into it as a second copy.

### `deployment: false`

Jobs naming `tend` use the mapping form. GitHub files a deployment
record for
every job that names an environment, against whatever ref the run
belongs to;
under `pull_request_target` that is the PR's own head, which is why PR
timelines grew a "worktrunk-bot deployed to tend" line on every push.
`deployment: false` drops the record and keeps the gate. The release
jobs keep
their records, which land in no PR timeline.

## Follow-up: one step, after merge

`TEND_BOT_TOKEN` is **already seeded into the `release` environment**
(read
from the local `worktrunk-bot` gh config dir at
`~/.config/gh-bots/worktrunk-bot`, so no new credential was minted and
nothing
was pasted). Verified: the token resolves to `worktrunk-bot` and has
push on
both `max-sixty/winget-pkgs` and `max-sixty/homebrew-worktrunk`.

That leaves one step, and it must come **after** this PR merges:

```
gh secret delete TEND_BOT_TOKEN --repo max-sixty/worktrunk
```

Not before. On `main` today the gist append, both
`create-issue-on-*-failure`
jobs, and the two publish jobs still read the token with no environment
named,
so deleting the repo-level copy first would break the next benchmarks
cron
(03:47 UTC daily). Merging this PR is what makes the deletion safe.

## What this does not fix

- `repo-secret-allowlist` still fails on `CLAUDE_CODE_OAUTH_TOKEN`, also
at
  repo level. It cannot be read back either; separate item.
- `environment-deployments` still fails on the generated `tend-*.yaml`,
which
  pin tend 0.1.13 and carry the bare `environment: tend`. Those are
regenerated by the published tend, and a regen also carries an unrelated
`gh api --paginate` fix in `tend-mention.yaml`, so it belongs in its own
PR.

## Verification

- The `append-gist` script was run end-to-end against a real
`benchmark-results-*` artifact from run 30976221483. It emits 40 rows
whose
`bench` names match the live gist's existing rows exactly, confirming
the
  artifact round-trip preserves paths relative to `target/criterion`.
- That a skipped `if` short-circuits the environment gate is confirmed
by run
31066000517: `publish-cargo`, which names `environment: release`,
completed
as *skipped* on a `pull_request` from a non-tag ref rather than failing
on
  the policy.
- `actionlint` reports the same eight pre-existing shellcheck notes as
`main`;
  no new findings. `pre-commit` passes.

> _This was written by Claude Code on behalf of max-sixty_
2026-08-06 02:58:00 -07:00
Maximilian Roos aa988b37bb ci(release): scope SIGNPATH_API_TOKEN to a dedicated signing environment (#3704)
`SIGNPATH_API_TOKEN` sits at repo level, where every workflow the repo
runs can read it. It is referenced once, by the "Submit SignPath signing
request" step in `build-local-artifacts`. This joins that job to a new
`signing` environment so the token can be held there instead.

The environment already exists, with a `v*` tag policy and no reviewer
rule. It holds no secret yet, and this PR is safe to merge before it
does: an environment secret *overrides* a repository one of the same
name rather than displacing access to it, so until `signing` holds a
token the job keeps reading the repo-level copy and signing behaves
exactly as it does today.

Two steps remain, and both need the token value, which is write-only and
so has to be set by hand — or re-issued from the SignPath console, which
rotates it at the same time:

```
gh secret set SIGNPATH_API_TOKEN --repo max-sixty/worktrunk --env signing
```

```
gh secret delete SIGNPATH_API_TOKEN --repo max-sixty/worktrunk
```

The delete is what clears the drift, and it is the one step with an
ordering constraint: run it after the environment secret exists, or the
next release signs with an empty token.

## Why a new environment rather than the existing `release`

Reusing `release` looks cheaper, and the usual objection to it turns out
to be false: `release` has no reviewer rule, so it would not have pulled
an approval gate into the build phase. Its only protection rule is a
`v*` tag policy, which is why `publish-cargo` and `publish-aur` deploy
to it unattended today.

The real problem is the other direction. A job that joins an environment
can read *every* secret in it, and `release` holds
`AUR_SSH_PRIVATE_KEY`. Putting `build-local-artifacts` there would give
the build phase the AUR deploy key, so the change would trade one
over-broad grant for another rather than removing one. `signing` holds
the single token its single consumer needs.

Allowlisting the secret in `.config/tend.yaml` was the third option. It
records "intentionally repo-wide", which is the wrong posture for a
credential that becomes a real code-signing key once the SignPath OSS
application clears. It is a self-signed test certificate today, which is
the argument for moving it now rather than after.

<details><summary>Verification</summary>

`.github/CLAUDE.md` claimed the `release` environment required
"deployment approval from `@max-sixty`". That was the source of the
approval-gate objection, and it was wrong:

```
$ gh api repos/max-sixty/worktrunk/environments/release
"protection_rules": [{"id": 48355233, "type": "branch_policy"}]

$ gh api repos/max-sixty/worktrunk/environments/release/deployment-branch-policies
{"branch_policies": [{"name": "v*", "type": "tag"}]}
```

No `required_reviewers` rule. The v0.71.0 deployment confirms it
behaviorally — `waiting` to `queued` in one second, with no approval in
between:

```
$ gh api repos/max-sixty/worktrunk/deployments/5682057674/statuses
success      2026-07-30T20:46:46Z
in_progress  2026-07-30T20:45:00Z
queued       2026-07-30T20:44:57Z
waiting      2026-07-30T20:44:56Z
```

That doc line is rewritten here, into a table of which environment holds
what and which job reads it.

Three other things worth confirming before touching a dist-generated
file:

- **Hand edits survive.** `dist-workspace.toml` sets `allow-dirty =
["ci"]`, and no job anywhere runs `dist generate --check`. The custom
`publish-cargo`, `publish-winget`, and `publish-aur` jobs already only
exist because of this.
- **The environment doesn't serialize the matrix.** `publish-cargo` and
`publish-aur` both target `release` and ran concurrently in the v0.71.0
release (started `20:44:58` and `20:44:59`), so the five matrix legs
won't queue behind each other.
- **tend only scans repo-level secrets.** `AUR_SSH_PRIVATE_KEY` and
`WINGET_TOKEN` sit in the `release` environment and `tend check` passes
them without complaint, so moving `SIGNPATH_API_TOKEN` to an environment
is what clears the check.

</details>

## Risk

Low. The repo-level token remains readable until it is deleted, so
signing is unaffected by the merge. Even with no token reachable at all,
the signing step is `continue-on-error: true` while the certificate is a
test one, so it would fail without blocking the crates.io, Homebrew,
winget, or AUR publishes — the one step that is deliberately not
`continue-on-error` just recomputes a checksum over whatever zip is in
place.

One coupling is now load-bearing and is noted in the workflow: the `v*`
tag policy means setting `pr-run-mode = "upload"` in
`dist-workspace.toml` would make GitHub reject this job on a PR ref.
Today `pr-run-mode` defaults to `plan`, so `build-local-artifacts` is
skipped on pull requests entirely — which also means this PR's own CI
does not exercise the change. The first real exercise is the next
release tag.

Ref #3572 — the issue closes once the repo-level secret is deleted.

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-01 23:09:43 -07:00
Maximilian Roos f1f1b50d85 docs(release): trim the signing archaeology now the path is proven (#3593)
Follow-up to #3590, now that v0.69.2 has shipped a signed Windows binary
— verified against the published asset rather than the logs:

```
git-wt.exe: certificate table 8480 bytes
wt.exe:     certificate table 8472 bytes
c4343fb5…1a43 *worktrunk-x86_64-pc-windows-msvc.zip   (published .sha256 matches)
```

Comments only; no behavior change.

The signing comments were written while the mechanism was still being
guessed at, so they carried the failed attempts — a ten-line account of
the zip-of-a-zip failure, a six-line account of the `…zip.zip`
collision. The path is proven and the workflow now verifies itself, so
what a reader needs is the current mechanism. Trimmed to that.

One thing added rather than removed. `Recompute checksum` sits between
two `continue-on-error` steps and looks like it should fold into the
replace step above it. It must not: the signing steps are tolerant
because publishing can't depend on a self-signed test certificate, while
a checksum that doesn't match the shipped zip has to fail the release.
That asymmetry is invisible in the YAML, so it's now stated — the next
person to simplify this shouldn't have to rediscover it.

> _This was written by Claude Code on behalf of max_
2026-07-25 03:22:07 -07:00
Maximilian Roos 6b29c2802b Release v0.69.2 (#3590)
Cuts v0.69.2, and fixes the Windows code-signing path it depends on.

## The signing fix

v0.69.1 shipped an unsigned `wt.exe` under a green run and a
**Completed** SignPath signing request. `archive: false` (#3566) had
already made the GitHub artifact name
`worktrunk-x86_64-pc-windows-msvc.zip`, and SignPath names its download
after the artifact — so with `output-artifact-directory: target/distrib`
the signed zip landed at `worktrunk-x86_64-pc-windows-msvc.zip.zip`,
beside the untouched unsigned build. The checksum step and the release
upload both kept reading the original. Confirmed by parsing the
published asset's PE certificate table: `size=0`.

The download now goes to a scratch directory and whatever single file
lands there replaces the built zip, so SignPath's naming isn't
load-bearing.

## Verification, because this failure is invisible

Signing is `continue-on-error` by design (self-signed test certificate
pending SignPath's OSS review), so nothing in the logs distinguishes
"signed" from "silently unsigned" — which is how it slipped through
twice, two different ways. `.github/verify-windows-signature.py` reads
the zip's PE certificate tables directly, and runs at two points with
distinct jobs:

- **before the overwrite** — an unsigned release is tolerable while the
certificate is a test one; a corrupt one never is, so the replacement
has to verify before it can clobber a good build.
- **after** — reports what the release actually ships, which is the
question the logs never answered.

## Rehearsed before landing

The signing path only runs on a tag, so each question about it used to
cost a release. This chain was instead run on a Windows runner against
the already-published v0.69.1 zip (identical bytes, no build):

```
saved to …\target\signpath\worktrunk-x86_64-pc-windows-msvc.zip.zip
git-wt.exe: certificate table 8480 bytes
wt.exe:     certificate table 8472 bytes
→ mv → target/distrib/worktrunk-x86_64-pc-windows-msvc.zip
target/distrib/worktrunk-x86_64-pc-windows-msvc.zip: all 2 executables signed
worktrunk-x86_64-pc-windows-msvc.zip: OK   (checksum matches)
```

That also settled the open question behind #3556: SignPath returns the
signed zip itself, not a wrapper, so `skip-decompress: true` is correct
— the extract mode does explode it into loose files.

## Release contents

`wt remove`'s fsmonitor sweep (#3581), the troubleshooting doc trim, and
this fix. The two refactors in range (#3582, #3584) are
behavior-preserving and omitted per convention.

Local gate green (4547 passed). Changelog entries verified against the
diffs by subagent; two claims corrected (the doc entry's rationale, and
an overclaim attributing v0.69.0's unsigned binary to this bug rather
than the separate upload failure #3566 fixed). Data-loss surface
reviewed across the cumulative diff.

> _This was written by Claude Code on behalf of max_
2026-07-24 20:02:13 -07:00
Maximilian Roos 7b741d0791 fix(release): stop double-zipping the SignPath upload artifact (#3566)
## Summary
- `actions/upload-artifact` wraps every upload in its own GitHub storage
zip unless `archive: false`. The uploaded file here is already a zip
(`worktrunk-x86_64-pc-windows-msvc.zip`), so the default produced a
zip-of-a-zip — SignPath treated the outer storage wrapper as "the
artifact" and the configured `<pe-file path="wt.exe">` never matched
anything inside it.
- Root-caused this against the real v0.69.0 release run: the SignPath
dashboard shows the failed request's unsigned artifact as
`unsigned-windows-zip.zip` (16.8MB, matching GitHub's storage-wrapper
name, not the real filename) with error `Expected path to match exactly
1 item, but found 0` for `wt.exe`.
- `archive: false` uploads the file as-is (single-file only, which is
what we have), so SignPath receives the real zip directly, one level
shallower — matching the artifact configuration as originally written.
- Also fixes the v0.69.0 CHANGELOG's SignPath entry, which read "Signed
with a test certificate" — overclaiming, since the actual signing
attempt on that release failed. Reworded to describe the pipeline's
intent rather than a specific run's result.

v0.69.0 shipped with an unsigned Windows binary as a result (signing
failure was masked by the intentional `continue-on-error`, so the
release itself succeeded — this is exactly the non-blocking behavior
that was designed in). This fix should make the next release's signing
attempt succeed for real.

## Test plan
- [x] `actionlint .github/workflows/release.yaml` — no new warnings
- [x] Root cause confirmed directly against the SignPath dashboard's
error details and artifact tab for the failed v0.69.0 signing request
- [x] Verified `archive: false` semantics against
`actions/upload-artifact@v7`'s own `action.yml` (single-file upload,
uploaded as-is)

> _This was written by Claude Code on behalf of Max_
2026-07-23 19:30:19 -07:00
Maximilian Roos 481125801f ci: publish to crates.io via trusted publishing (#3564)
## What

`publish-cargo` now mints its crates.io credential per run through
`rust-lang/crates-io-auth-action` (GitHub Actions OIDC) instead of
reading
the `CARGO_REGISTRY_TOKEN` environment secret. The job gains
`id-token: write` for the OIDC exchange and `contents: read` for
checkout,
narrowing it from the workflow-level `contents: write`.

The token lives for about 30 minutes and the action's post step revokes
it,
so no long-lived publish credential exists anywhere.

## Why

The stored token expires on a schedule, and each expiry is a silent
trap:
nothing breaks until the next release tag, which is exactly when you
don't
want to discover it.

## Prerequisite, already in place

A Trusted Publisher is configured for `worktrunk` on crates.io —
repository `max-sixty/worktrunk`, workflow `release.yaml`, environment
`release`. It had to land before this merge, since otherwise
`publish-cargo` would fail at the auth step on the next release tag.

`CARGO_REGISTRY_TOKEN` can be deleted from the `release` environment
once a release has gone out this way. `AUR_SSH_PRIVATE_KEY` stays.

> _This was written by Claude Code on behalf of max_
2026-07-23 18:46:12 -07:00
Maximilian Roos 8f55d15301 fix(release): preserve signed Windows zip filename, match checksum format (#3556)
## Summary
- The SignPath action's `skip-decompress` defaults to `false`, so it
would have extracted the returned zip's contents as loose files into
`target/distrib/` instead of saving back a signed
`worktrunk-x86_64-pc-windows-msvc.zip`. The checksum step would have
silently hashed the still-unsigned zip, and the release would have
shipped unsigned Windows binaries with no CI failure to flag it.
- `sha256sum` without `-b` omits the `*` binary-mode marker;
cargo-dist's own checksums use `<hash> *<filename>` (confirmed against a
real release asset). Added `-b` to match.

Confirmed via `gh run view` on #3553's own CI run that
`build-local-artifacts` is skipped on PRs in this repo, so this code
path has never actually executed — this is the first real fix before it
runs for real on a tagged release.

## Test plan
- [x] `actionlint .github/workflows/release.yaml` — no new warnings
(same pre-existing shellcheck style notes as before)
- [x] Verified `skip-decompress` behavior against the action's own
`action.yml` input spec
- [x] Verified checksum format against a real downloaded release asset
(`v0.68.0`)

> _This was written by Claude Code on behalf of Max_
2026-07-23 16:13:30 -07:00
Maximilian Roos 5f8c301dec feat(release): sign Windows binaries via SignPath (#3553)
## Summary
- Signs the Windows release zip (`wt.exe` + `git-wt.exe`) via
[SignPath](https://signpath.io)'s free OSS code-signing program, using
the `test-signing` policy (self-signed test certificate) while the
project's Foundation-program application is under review.
- Non-blocking (`continue-on-error`) so a signing hiccup can't take down
crates.io/homebrew/winget/AUR publishing.
- Recomputes the `.sha256` checksum after signing, since the signed
zip's bytes differ from the unsigned one.
- Uses a dedicated low-privilege `CI builds` SignPath identity
(submitter-only), not an admin account.

## Test plan
- [x] `actionlint` clean (only pre-existing shellcheck style warnings
elsewhere in the file)
- [x] Artifact configuration (zip containing `wt.exe` + `git-wt.exe`)
validated against SignPath's own XML parser and against the real file
layout inside a downloaded `v0.68.0` Windows release zip
- [ ] First real Windows build after merge will be the first live
signing round-trip through GitHub Actions — watch that release's CI run

> _This was written by Claude Code on behalf of Max_

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 12:19:32 -07:00
dependabot[bot] 013d1cc221 chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.3 to 4.2.0 (#3472)
Bumps
[KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur)
from 4.1.3 to 4.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's
releases</a>.</em></p>
<blockquote>
<h2>v4.2.0</h2>
<p>Add a feature to sync AUR repo (<a
href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/52">KSXGitHub/github-actions-deploy-aur#52</a>).</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/084b0d9b15415bf9cdb65d44dad1efe37a354050"><code>084b0d9</code></a>
style: consistency (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/55">#55</a>)</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/9e2f21095c586521806151200746082d8e02bb90"><code>9e2f210</code></a>
fix: force-add <code>PKGBUILD</code> and <code>.SRCINFO</code> in the
asset_dir/assets path (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/53">#53</a>)</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/7acb32fe8c43848121eee16dd39d8294ec2bf25b"><code>7acb32f</code></a>
feat: full asset sync (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/52">#52</a>)</li>
<li>See full diff in <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.3...v4.2.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=KSXGitHub/github-actions-deploy-aur&package-manager=github_actions&previous-version=4.1.3&new-version=4.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-19 11:21:35 -07:00
dependabot[bot] 9e8d4612c8 chore: bump actions/checkout from 6 to 7 (#3131)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to
7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>block checking out fork pr for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
<li>getting ready for checkout v7 release by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
<li>update error wording by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
<h2>v6.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Update changelog by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>Update changelog for v6.0.3 by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
<h2>v6.0.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID
is set by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p>
<h2>v6.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Update all references from v5 and v4 to v6 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
<li>Clarify v6 README by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
update error wording (<a
href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
getting ready for checkout v7 release (<a
href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
Bump the minor-npm-dependencies group across 1 directory with 3 updates
(<a
href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
upgrade module to esm and update dependencies (<a
href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
and Remove uuid (<a
href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
Bump js-yaml from 4.1.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
Bump flatted from 3.3.1 to 3.4.2 (<a
href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
Bump actions/publish-immutable-action (<a
href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
block checking out fork pr for pull_request_target and workflow_run (<a
href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/checkout/compare/v6...v7">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 14:03:53 -07:00
Worktrunk Bot fbe9aea898 ci: rename WORKTRUNK_BOT_TOKEN → TEND_BOT_TOKEN in non-tend workflows (#2781)
Per [@max-sixty's request on
#2776](https://github.com/max-sixty/worktrunk/pull/2776#issuecomment-4472516748):
finish the `WORKTRUNK_BOT_TOKEN` → `TEND_BOT_TOKEN` rename in the
non-tend workflows that #2776 left behind.

## Changes

- `.github/workflows/nightly.yaml` — gist append (`GITHUB_TOKEN` on the
`💾 Append results to gist` step) and the failure-issue creator
(`JasonEtco/create-an-issue`). Comments updated to match.
- `.github/workflows/release.yaml` — `GH_TOKEN` for the winget-pkgs fork
sync, the `winget-releaser@v2` token, and the homebrew-worktrunk
checkout token.
- `.github/CLAUDE.md` — Tokens table now lists `TEND_BOT_TOKEN`.

## Why this is safe

Both secrets currently point at the same PAT (per #2773), so this is a
name-only swap — no permission or scope change. The tend-managed
workflows already migrated in #2776; this PR catches the ones tend's
regen doesn't touch.

After merge, the obsolete `WORKTRUNK_BOT_TOKEN` (and `BOT_TOKEN`) secret
can be deleted from repo settings — tracked in #2775.

## Test plan

- [ ] CI green on this PR
- [ ] Next scheduled `nightly` run successfully appends to the benchmark
gist
- [ ] Next release publish reaches winget + homebrew

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-17 14:31:16 -07:00
dependabot[bot] 99d9307b11 chore: bump KSXGitHub/github-actions-deploy-aur from 4.1.2 to 4.1.3 (#2312)
Bumps
[KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur)
from 4.1.2 to 4.1.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/releases">KSXGitHub/github-actions-deploy-aur's
releases</a>.</em></p>
<blockquote>
<h2>v4.1.3</h2>
<p>There is a bug in <code>runuser</code> that converts all
<code>-c</code> (even after <code>--</code>) into <code>--command</code>
which <code>bash</code> doesn't recognize. This release removes the
<code>-c</code> flag entirely, bash would execute <code>/build.sh</code>
as if it's a file. Hopefully, the behavior preserves. If not, maybe just
switch to <code>su</code> or <code>sudo</code>.</p>
<p>Relevant PR: <a
href="https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51">KSXGitHub/github-actions-deploy-aur#51</a>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7"><code>da03e16</code></a>
fix: <code>bash: --command: invalid option</code> (<a
href="https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51">#51</a>)</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1"><code>3b403c7</code></a>
docs(readme): use the GitHub's note syntax</li>
<li><a
href="https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2"><code>e17cd79</code></a>
docs(readme): remove patreon</li>
<li>See full diff in <a
href="https://github.com/ksxgithub/github-actions-deploy-aur/compare/v4.1.2...v4.1.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=KSXGitHub/github-actions-deploy-aur&package-manager=github_actions&previous-version=4.1.2&new-version=4.1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-19 21:02:51 -07:00
Maximilian Roos da19f329e5 fix: bump AUR deploy action to v4.1.2 (#1909)
Arch Linux updated util-linux with stricter `runuser` argument parsing
in su-compatible mode. The v4.1.1 entrypoint ran `runuser builder
--command 'bash -l -c /build.sh'`, but with the username before
`--command`, the new `runuser` passes `--command` as a shell argument to
bash — producing `bash: --command: invalid option`. This broke the
v0.34.1 AUR publish.

v4.1.2
([KSXGitHub/github-actions-deploy-aur#49](https://github.com/KSXGitHub/github-actions-deploy-aur/pull/49),
released 2026-04-03) switches to `runuser -u builder -- bash -l -c
/build.sh`.

> _This was written by Claude Code on behalf of @max-sixty_

Co-authored-by: Claude <noreply@anthropic.com>
2026-04-04 13:35:51 -07:00
worktrunk-bot 8a0404de49 ci: remove dist binary caching from release workflow (#1299)
## Summary

- Remove the `cargo-dist-cache` artifact pattern that shared the `dist`
binary between release jobs
- Install `dist` fresh via the official installer script in
`build-global-artifacts` and `host` jobs (same as `plan` and
`build-local-artifacts` already do)
- Ensures a poisoned cache cannot affect release artifacts

Closes #1298

## Test plan

- [ ] Release workflow YAML is valid (CI will run the `plan` job on this
PR)
- [ ] Each job that needs `dist` installs it independently

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 04:11:15 +00:00
dependabot[bot] 51c9e586bd chore: bump actions/download-artifact from 7 to 8 (#1218) 2026-02-26 23:45:42 -08:00
dependabot[bot] 2a67c5e787 chore: bump actions/upload-artifact from 6 to 7 (#1217) 2026-02-26 23:45:01 -08:00
Maximilian Roos bd188aa7ef CI security model: rulesets, token consolidation, environment protection (#1118)
## Summary

- Consolidate all Claude workflows to `WORKTRUNK_BOT_TOKEN` for
consistent identity. The merge restriction (ruleset) is the security
boundary, not token scoping.
- Review workflow: `contents: read`, BOT_TOKEN for API calls, sticky
comment
- Mention workflow: add PR branch checkout for
`pull_request_review_comment` events
- Add `.github/CLAUDE.md` documenting the full security model: threat
model, token strategy, branch protection, environment protection

Infrastructure changes (via API, not in code):
- Ruleset "Merge access" on `main`: "Restrict updates" rule, admin
exempt bypass
- GitHub Environment `release` with deployment protection (`v*` tags
only)
- Deleted `WORKTRUNK_REVIEW_TOKEN` from repo secrets
- Moved `CARGO_REGISTRY_TOKEN` to `release` environment

## Test plan

- [ ] Verify review workflow posts as `worktrunk-bot` (this PR triggers
it)
- [ ] Verify `@claude` mention works on issues and PR review comments
- [ ] Verify admin can merge without bypass checkbox friction
- [ ] Verify bot cannot merge PRs (ruleset blocks non-admin)

> _This was written by Claude Code on behalf of @max-sixty_

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-02-19 15:52:25 -08:00
Maximilian Roos 48c6b97385 docs(release): improve install instructions in release notes (#918)
- Replace tap formula (max-sixty/worktrunk/wt) with homebrew-core (worktrunk)
- Add shell install suffix to all install commands
- Add Cargo, Winget, and AUR install options

Co-authored-by: Claude <noreply@anthropic.com>
2026-02-02 08:50:53 -08:00
Maximilian Roos dfcbeaab01 chore(ci): pin runner versions and add weekly renovation workflow (#878)
* chore(ci): pin runner versions and add weekly renovation workflow

Pin all GitHub Actions runners to specific versions instead of using -latest
labels to avoid surprise breaking changes from migrations (like the recent
Windows 2025 D: drive issue).

Pinned versions:
- ubuntu-24.04 (current ubuntu-latest)
- macos-15 (current macos-latest)
- windows-2022 (windows-2025 lacks D: drive, actions/runner-images#12677)

Also adds claude-renovate.yaml workflow that runs weekly to check for:
- Runner version updates
- GitHub Actions version updates
- Rust nightly version updates for cargo-udeps

Co-Authored-By: Claude <noreply@anthropic.com>

* Use stable job names for test matrix

Use `test (linux)`, `test (macos)`, `test (windows)` instead of
embedding version numbers in job names. This way branch protection
rules don't need updating when runner versions change.

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-01-26 16:51:11 -08:00
Maximilian Roos 55e841e0b8 Add AUR publish workflow (#585)
* Add AUR publish workflow

- Add PKGBUILD template in .github/aur/
- Add publish-aur job to release workflow using github-actions-deploy-aur
- Uses updpkgsums to auto-calculate checksums from release assets

Requires AUR_SSH_PRIVATE_KEY secret to be configured.

Co-Authored-By: Claude <noreply@anthropic.com>

* Update .github/aur/PKGBUILD

Co-authored-by: Evan Sosenko <razorx@evansosenko.com>

* Address AUR package review feedback

- Remove git-wt binary (not needed for Arch users)
- Add fish completions to standard location

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Evan Sosenko <razorx@evansosenko.com>
2026-01-16 00:09:49 -08:00
Maximilian Roos 2e5e9aefbd refactor(ci): use cargo-dist for Homebrew formula generation (#593)
* refactor(ci): use cargo-dist for Homebrew formula generation

Replace manual sed-based formula updates with cargo-dist's built-in
Homebrew publishing:

- Add `homebrew` to installers in dist-workspace.toml
- Configure tap and formula name
- Replace publish-homebrew job to use the formula generated by cargo-dist
- Add homepage to Cargo.toml (required by cargo-dist)

This eliminates the fragile sed patterns that previously broke when
updating SHA256 hashes, as cargo-dist now generates the complete formula
with correct multi-arch support.

Co-Authored-By: Claude <noreply@anthropic.com>

* simplify: remove complex JSON parsing from publish-homebrew

cargo-dist generates a single wt.rb - no need to parse PLAN JSON
to find artifacts or handle multiple packages.

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-01-13 11:06:19 -08:00
Maximilian Roos cb7a32f48a fix(ci): correct SHA256 hash updates in Homebrew formula (#591)
The previous sed commands used "0,/pattern/s//" to replace the "first
match", but after each replacement the new hash was still a valid 64-char
hex string, so subsequent seds kept matching and overwriting the same
line. This left the first sha256 with the Linux hash while the Intel and
Linux positions were never updated.

Fix by matching each URL pattern and updating the sha256 on the next line
using sed's {n;s/...} syntax, ensuring each hash is updated independently.

Co-authored-by: Claude <noreply@anthropic.com>
2026-01-13 02:26:08 -08:00
Maximilian Roos aeffd687fc ci: automate Homebrew formula updates in release workflow
Add publish-homebrew job that:
- Clones homebrew-worktrunk using bot token
- Fetches SHA256 hashes from release assets
- Updates formula with sed
- Commits and pushes

Also updates release skill to reflect full automation.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-01-11 16:27:17 -08:00
Maximilian Roos a1283dae16 ci: sync winget-pkgs fork before publishing
The winget publish job was failing because the fork of
microsoft/winget-pkgs was thousands of commits behind upstream.
Komac couldn't create a branch from such an outdated base.

Add a step to sync the fork with upstream before publishing.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-12-30 22:32:35 -08:00
Maximilian Roos d3f34b85ef Enable automatic winget package publishing (#241)
Uncomment and configure the publish-winget job to automatically submit
PRs to winget-pkgs on new releases using vedantmgoyal9/winget-releaser.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-17 10:23:40 -08:00
dependabot[bot] d884c6f962 chore: bump actions/download-artifact from 6 to 7 (#200)
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 6 to 7.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](https://github.com/actions/download-artifact/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-14 20:29:35 -08:00
dependabot[bot] 7ed748cf92 chore: bump actions/upload-artifact from 5 to 6 (#201)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 5 to 6.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-14 20:29:29 -08:00
Maximilian Roos 4e63480fa2 Remove unnecessary --locked flags from CI
Cargo.lock is committed and updated by cargo check before commits.
--locked adds overhead without providing value for this workflow.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-12-10 17:41:24 -08:00
Maximilian Roos 8af4cbbc77 Fix cargo publish to specify package explicitly
The workspace has dev-detach in default-members for cargo test builds.
Specify --package worktrunk to avoid attempting to publish dev-detach.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-12-10 17:28:22 -08:00
Maximilian Roos 1590855c43 Disable winget publishing until initial package submission
The winget-releaser action requires the package to already exist in
the winget-pkgs repository. Manual initial submission is required:
https://github.com/microsoft/winget-pkgs/blob/master/CONTRIBUTING.md

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-12-10 04:14:48 -08:00
Maximilian Roos 079c9df3fb Add winget publish job to release workflow
Add a new publish-winget job that publishes releases to Windows Package
Manager. This job runs after the plan and host jobs, uses the winget-releaser
action to publish the release, and is added as a dependency for the announce
job to ensure it completes before announcement.
2025-12-10 00:01:42 -08:00
Maximilian Roos 976ebce4c7 Remove unnecessary dtolnay/rust-toolchain from CI workflows (#115)
GitHub runners (ubuntu-latest, macos-latest, windows-latest) come with Rust
stable pre-installed including rustfmt and clippy. The explicit toolchain
installation step is unnecessary.

This matches how prql handles Rust setup - they don't use dtolnay/rust-toolchain
at all and rely on the pre-installed Rust.

Removed from:
- ci.yaml: test job and benchmarks job
- claude.yaml: Claude Code action job
- release.yaml: publish-cargo job

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-08 14:28:25 -08:00
Maximilian Roos 112b95a762 Add explicit workflow names and standardize to lowercase format
Workflow files now include explicit `name` fields at the top and use lowercase naming convention. This improves workflow visibility and consistency in GitHub Actions UI.
2025-12-04 18:22:03 -08:00
Maximilian Roos 28aaab33a5 Add workflow names for cleaner CI check display (#80)
GitHub shows file paths when workflows lack names. Adding `name: CI` and
`name: Release` gives cleaner check names like "CI / test (macos-latest)"
instead of ".github/workflows/ci.yaml / test (macos-latest)".

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 11:16:21 -08:00
Maximilian Roos 464647c29b ci: Standardize workflow file naming (#67)
* ci: Standardize workflow file naming

- Rename all workflow files from .yml to .yaml for consistency
- Remove workflow and job name: fields (use job IDs as display names)
- Update references to renamed files in publish-docs and README badge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: Generate command reference from `help --md`

- Replaces static command documentation in `docs/content/commands.md` with auto-generated content from `wt <command> --help-md`.
- Moves advanced tips and patterns to a new `docs/content/tips-patterns.md` page.
- Updates navigation weights and `wt select` documentation to reflect these changes.
- Adds an integration test to ensure the generated documentation remains in sync with the CLI help output.

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-01 07:34:24 -08:00