From cf41393e732bee8c05885ac07ea2815b9f3d9378 Mon Sep 17 00:00:00 2001 From: Sergei Romanov Date: Thu, 17 Sep 2026 10:35:58 +1000 Subject: [PATCH 1/2] Constly cask: add livecheck; add tap CI workflow livecheck reads the version from downloads.constly.com/latest.json so brew livecheck, brew bump-cask-pr and the online audit work. The tests workflow runs brew test-bot tap-syntax on push, pull request and a weekly schedule. Developer mode is on under brew audit, so a Homebrew deprecation fails the run instead of surfacing as a warning on users' machines. --- .github/dependabot.yml | 10 ++++++++ .github/workflows/tests.yml | 46 +++++++++++++++++++++++++++++++++++++ Casks/constly.rb | 7 ++++++ 3 files changed, 63 insertions(+) create mode 100644 .github/dependabot.yml create mode 100644 .github/workflows/tests.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..09c446a --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directory: "/" + schedule: + interval: weekly + groups: + github-actions: + patterns: + - "*" diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml new file mode 100644 index 0000000..0c152fb --- /dev/null +++ b/.github/workflows/tests.yml @@ -0,0 +1,46 @@ +name: brew test-bot + +on: + push: + branches: + - main + pull_request: + schedule: + # Weekly, so a Homebrew deprecation that lands between cask bumps still + # shows up here before it starts breaking `brew update` for users. + - cron: "20 7 * * 1" + workflow_dispatch: + +permissions: {} + +defaults: + run: + shell: bash -xeuo pipefail {0} + +jobs: + test-bot: + runs-on: macos-26 + permissions: + actions: read + checks: read + contents: read + pull-requests: read + steps: + - name: Set up Homebrew + id: set-up-homebrew + uses: Homebrew/actions/setup-homebrew@f8d4222eb633e65c2a0157383cf80861fc7fae7f # 2026.09.07.1 + with: + token: ${{ secrets.GITHUB_TOKEN }} + + - name: Cache Homebrew Bundler RubyGems + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: ${{ steps.set-up-homebrew.outputs.gems-path }} + key: macos-26-rubygems-${{ steps.set-up-homebrew.outputs.gems-hash }} + restore-keys: macos-26-rubygems- + + - run: brew test-bot --only-cleanup-before + + - run: brew test-bot --only-setup + + - run: brew test-bot --only-tap-syntax diff --git a/Casks/constly.rb b/Casks/constly.rb index feec128..c7d5f9f 100644 --- a/Casks/constly.rb +++ b/Casks/constly.rb @@ -10,6 +10,13 @@ desc "WYSIWYG markdown editor that renders the marks away as you type" homepage "https://constly.com/" + livecheck do + url "https://downloads.constly.com/latest.json" + strategy :json do |json| + json["version"] + end + end + # Constly ships its own signed, minisign-verified auto-updater; let it drive # upgrades so brew never fights the in-app update (per RTW distribution # decision, 7 Aug 2026). `brew upgrade` becomes a no-op for this cask. From 7181331eefc09480056b83cd67cca28e7693ab05 Mon Sep 17 00:00:00 2001 From: Sergei Romanov Date: Thu, 17 Sep 2026 10:54:18 +1000 Subject: [PATCH 2/2] livecheck: validate version with a regex; CI: pin developer mode, run online audit weekly The JSON strategy block now runs the version through a regex, so a pre-release such as 4.8.0-beta.1 is ignored, a v prefix is stripped, and a non-string value yields no version instead of raising. The workflow sets HOMEBREW_DEVELOPER so any audit step fails on deprecations, checks that setup-homebrew detected the tap, and runs the online cask audit and livecheck on the weekly schedule, since test-bot's tap-syntax audit is offline. --- .github/workflows/tests.yml | 44 +++++++++++++++++++++++++++---------- Casks/constly.rb | 5 +++-- 2 files changed, 35 insertions(+), 14 deletions(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 0c152fb..f498209 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -6,25 +6,38 @@ on: - main pull_request: schedule: - # Weekly, so a Homebrew deprecation that lands between cask bumps still - # shows up here before it starts breaking `brew update` for users. + # Weekly canary. Homebrew deprecations that land between cask bumps show + # up here first, and the online audit below checks that latest.json is + # still reachable and that livecheck still resolves the current version. + # Note: GitHub disables scheduled runs on a public repo after 60 days + # without a commit; re-enable the workflow if that happens. - cron: "20 7 * * 1" workflow_dispatch: permissions: {} +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + defaults: run: shell: bash -xeuo pipefail {0} +env: + # test-bot sets this itself, but pin it so a plain `brew audit` step in this + # workflow also fails hard on deprecations instead of staying silent. + HOMEBREW_DEVELOPER: 1 + TAP: runthewall/tap + jobs: test-bot: - runs-on: macos-26 + strategy: + matrix: + os: [ macos-26 ] + runs-on: ${{ matrix.os }} permissions: - actions: read - checks: read contents: read - pull-requests: read steps: - name: Set up Homebrew id: set-up-homebrew @@ -32,15 +45,22 @@ jobs: with: token: ${{ secrets.GITHUB_TOKEN }} + - name: Check the tap was detected + run: test "${{ steps.set-up-homebrew.outputs.tap-name }}" = "$TAP" + - name: Cache Homebrew Bundler RubyGems uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: ${{ steps.set-up-homebrew.outputs.gems-path }} - key: macos-26-rubygems-${{ steps.set-up-homebrew.outputs.gems-hash }} - restore-keys: macos-26-rubygems- - - - run: brew test-bot --only-cleanup-before - - - run: brew test-bot --only-setup + key: ${{ matrix.os }}-rubygems-${{ steps.set-up-homebrew.outputs.gems-hash }} + restore-keys: ${{ matrix.os }}-rubygems- - run: brew test-bot --only-tap-syntax + + # The tap-syntax audit is offline, so livecheck is only parsed there. + # Run it for real once a week. + - name: Online audit and livecheck + if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' + run: | + brew audit --cask --online --tap="$TAP" + brew livecheck --cask --tap "$TAP" diff --git a/Casks/constly.rb b/Casks/constly.rb index c7d5f9f..22de817 100644 --- a/Casks/constly.rb +++ b/Casks/constly.rb @@ -12,8 +12,9 @@ livecheck do url "https://downloads.constly.com/latest.json" - strategy :json do |json| - json["version"] + regex(/^v?(\d+(?:\.\d+)+)$/i) + strategy :json do |json, regex| + json["version"].to_s[regex, 1] end end