From 93d650f540fb8a64bda0ff546aaf5a61068f337a Mon Sep 17 00:00:00 2001 From: Ernesto Ongaro Date: Mon, 21 Sep 2026 12:48:28 +0100 Subject: [PATCH] docs: describe the tap deploy key instead of the retired PAT The release prerequisites still told readers to set HOMEBREW_TAP_GITHUB_TOKEN with contents:write on the tap. That secret was replaced in #102 by an ed25519 deploy key scoped to the tap alone. Also record the protect-main ruleset, since the deploy-key bypass is what keeps the release workflow able to push to main while everyone else goes through a pull request. Co-Authored-By: Claude Opus 5 (1M context) --- DEVELOPMENT.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/DEVELOPMENT.md b/DEVELOPMENT.md index 318f2ce..630ad26 100644 --- a/DEVELOPMENT.md +++ b/DEVELOPMENT.md @@ -104,7 +104,8 @@ The phase-1 tap formula is intentionally separate from the eventual `homebrew/co For the release workflow to publish the tap formula, the following must be in place: - The public tap repo `exploreomni/homebrew-tap` exists with `main` as its default branch. -- The `HOMEBREW_TAP_GITHUB_TOKEN` secret is set on the `exploreomni/cli` repo. This token needs `contents:write` access to `exploreomni/homebrew-tap` so GitHub Actions can update the tap from the release workflow. +- The `HOMEBREW_TAP_DEPLOY_KEY` secret is set on the `exploreomni/cli` repo, holding the private half of an ed25519 deploy key. The public half is registered on `exploreomni/homebrew-tap` with write access, so GitHub Actions can update the tap from the release workflow. The key is scoped to the tap alone — it grants nothing anywhere else. +- The tap's `protect-main` ruleset requires pull requests on `main` and lists deploy keys as a bypass actor, so the release workflow is the only thing that can push to it directly. ### What Gets Built