Skip to content

Constly cask: add livecheck and tap CI - #2

Merged
ikwach merged 2 commits into
mainfrom
feat/livecheck-and-ci
Sep 17, 2026
Merged

ikwach merged 2 commits into
mainfrom
feat/livecheck-and-ci

Conversation

@ikwach

@ikwach ikwach commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Two follow-ups to #1.

livecheck. The cask had no livecheck block, so brew audit --online failed with "Version '4.7.1' differs from '' retrieved by livecheck", and brew livecheck and brew bump-cask-pr were unusable. The release feed at downloads.constly.com/latest.json already publishes the version, so the block reads it with the JSON strategy. The value goes through a regex, so a pre-release such as 4.8.0-beta.1 is ignored rather than proposed as a bump, a v prefix is stripped, and a non-string value yields no version instead of raising. brew livecheck --cask runthewall/tap/constly reports 4.7.1, and HOMEBREW_DEVELOPER=1 brew audit --cask --online --strict passes.

CI. The tap had no workflow. The verified: parameter that #1 removed shipped in two cask bumps after Homebrew had started rejecting it in brew audit, and nobody noticed until the user-facing warning in 7.0. This adds the brew tap-new tests workflow, trimmed to the tap-syntax job on macOS since the tap only has a cask. It runs on push to main, on pull requests, and weekly.

Deprecations fail the run because HOMEBREW_DEVELOPER is set; test-bot sets it internally, and the workflow pins it at workflow level so a plain brew audit step behaves the same way. The tap-syntax audit is offline, so the weekly run also does the online cask audit and a real livecheck against latest.json. Once latest.json advertises a version newer than the cask, that weekly run fails with "Version 4.7.1 differs from ..." until the cask is bumped. That failure email means "bump the cask", not that something broke. The job checks that setup-homebrew detected the tap name, so a repo rename cannot silently audit homebrew/core instead. A dependabot config keeps the pinned action SHAs current.

Two things this does not do, for follow-up: main has no branch protection, so a direct push still reaches users before the check reports; and GitHub disables the schedule on a public repo after 60 days without commits, so the weekly canary needs a commit or a manual re-enable between releases.

Version, checksums and artifacts are unchanged.

livecheck reads the version from downloads.constly.com/latest.json so
brew livecheck, brew bump-cask-pr and the online audit work.

The tests workflow runs brew test-bot tap-syntax on push, pull request
and a weekly schedule. Developer mode is on under brew audit, so a
Homebrew deprecation fails the run instead of surfacing as a warning
on users' machines.
… online audit weekly

The JSON strategy block now runs the version through a regex, so a
pre-release such as 4.8.0-beta.1 is ignored, a v prefix is stripped,
and a non-string value yields no version instead of raising.

The workflow sets HOMEBREW_DEVELOPER so any audit step fails on
deprecations, checks that setup-homebrew detected the tap, and runs
the online cask audit and livecheck on the weekly schedule, since
test-bot's tap-syntax audit is offline.
@ikwach
ikwach merged commit 79f656f into main Sep 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant