From 6ac42cad371554895a86f18461fee8483cdf49b1 Mon Sep 17 00:00:00 2001 From: Joel Scheuner Date: Tue, 22 Sep 2026 14:59:49 +0200 Subject: [PATCH 1/4] Add CI to style and audit the tap Co-Authored-By: Claude --- .github/workflows/ci.yml | 63 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 .github/workflows/ci.yml diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..6720cb2 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,63 @@ +name: Tap CI + +# Content reaches this tap two ways -- release bots push generated files to +# main, and people hand-edit them (#8) -- and neither is checked today. The +# deprecated `postflight` stanza (#7) shipped that way and survived two +# releases. +on: + push: + branches: [main] + pull_request: + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }} + cancel-in-progress: true + +jobs: + audit: + name: Style and audit + # Casks are macOS artifacts, and the runner ships Homebrew. + runs-on: macos-latest + timeout-minutes: 20 + steps: + - name: Check out the tap + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: tap + + # Audit and the cask cops both resolve a tap name, not a path, so the + # checkout has to stand in as the real tap. + - name: Install the checkout as localstack/tap + run: | + dest="$(brew --repository)/Library/Taps/localstack/homebrew-tap" + mkdir -p "$(dirname "${dest}")" + rm -rf "${dest}" + cp -R tap "${dest}" + + # TODO(localstack/lstk#512): drop --except-cops. The next lstk release + # regenerates this cask with the quarantine stanza first, which trips + # Cask/StanzaOrder on every stanza after it until the install_steps form + # lands upstream. Scoped to that one cop, so Cask/InstallSteps -- the cop + # that catches #7 -- still fires. + - name: Style the cask + run: brew style --except-cops=Cask/StanzaOrder --cask localstack/tap/lstk + + # Why this job earns its keep: --online fetches every url and verifies + # every checksum. lstk's own CI renders the cask before the release it + # points at exists, so it cannot check either. + - name: Audit the cask + run: brew audit --cask --online localstack/tap/lstk + + # Not blocking yet: the formula is generated by localstack-cli's Homebrew + # Releaser and has 7 pre-existing problems, including a non-standard SPDX + # license. Reported so they are visible; TODO: make this blocking once + # that generator emits a clean formula. + - name: Style and audit the formula + continue-on-error: true + run: | + brew style --formula localstack/tap/localstack-cli + brew audit --formula --online localstack/tap/localstack-cli From 1c472b28bbd746d74ca185fbad647b3e3124d69f Mon Sep 17 00:00:00 2001 From: Joel Scheuner Date: Tue, 22 Sep 2026 15:51:53 +0200 Subject: [PATCH 2/4] Authenticate the online audit and always run the formula checks Co-Authored-By: Claude --- .github/workflows/ci.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6720cb2..48176db 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -23,6 +23,10 @@ jobs: # Casks are macOS artifacts, and the runner ships Homebrew. runs-on: macos-latest timeout-minutes: 20 + # `brew audit --online` queries the GitHub API, and the runners share IPs + # that are already over the unauthenticated rate limit. + env: + HOMEBREW_GITHUB_API_TOKEN: ${{ secrets.GITHUB_TOKEN }} steps: - name: Check out the tap uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -56,7 +60,10 @@ jobs: # Releaser and has 7 pre-existing problems, including a non-standard SPDX # license. Reported so they are visible; TODO: make this blocking once # that generator emits a clean formula. + # `always()` because continue-on-error only forgives this step's own + # failure; without it a failing cask check above skips this one. - name: Style and audit the formula + if: always() continue-on-error: true run: | brew style --formula localstack/tap/localstack-cli From b54900577419e24f2ebf0a51ca1708bcfb87e648 Mon Sep 17 00:00:00 2001 From: Joel Scheuner Date: Tue, 22 Sep 2026 15:54:47 +0200 Subject: [PATCH 3/4] Run the formula audit even when its style check fails Co-Authored-By: Claude --- .github/workflows/ci.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 48176db..02e374e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -61,10 +61,15 @@ jobs: # license. Reported so they are visible; TODO: make this blocking once # that generator emits a clean formula. # `always()` because continue-on-error only forgives this step's own - # failure; without it a failing cask check above skips this one. + # failure; without it a failing cask check above skips this one. `|| rc=1` + # because the shell runs under `-e`, so a failing style run would + # otherwise abort before the audit -- the half that catches the version + # and license problems. - name: Style and audit the formula if: always() continue-on-error: true run: | - brew style --formula localstack/tap/localstack-cli - brew audit --formula --online localstack/tap/localstack-cli + rc=0 + brew style --formula localstack/tap/localstack-cli || rc=1 + brew audit --formula --online localstack/tap/localstack-cli || rc=1 + exit "${rc}" From 745328b42cbe47185f25ebd267f1a2327fa978a8 Mon Sep 17 00:00:00 2001 From: Joel Scheuner Date: Tue, 22 Sep 2026 17:53:15 +0200 Subject: [PATCH 4/4] Point the formula TODO at the upstream fix and trim its comment Co-Authored-By: Claude --- .github/workflows/ci.yml | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 02e374e..ca4b9a3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -56,15 +56,12 @@ jobs: - name: Audit the cask run: brew audit --cask --online localstack/tap/lstk - # Not blocking yet: the formula is generated by localstack-cli's Homebrew - # Releaser and has 7 pre-existing problems, including a non-standard SPDX - # license. Reported so they are visible; TODO: make this blocking once - # that generator emits a clean formula. - # `always()` because continue-on-error only forgives this step's own - # failure; without it a failing cask check above skips this one. `|| rc=1` - # because the shell runs under `-e`, so a failing style run would - # otherwise abort before the audit -- the half that catches the version - # and license problems. + # TODO(localstack/localstack-cli#57): drop continue-on-error once a release + # regenerates the formula from that fix. Reported not enforced until then: + # the generator emits 7 problems, and fixing them here would be overwritten. + # + # `always()` so a failing cask check above does not skip this; `|| rc=1` + # because `-e` would otherwise abort before the audit. - name: Style and audit the formula if: always() continue-on-error: true