项目文件夹

文件
Tam Nguyen Duc 7483efd2a9 Dequarantine the brew cask binary on install (#67)
Homebrew quarantines cask artifacts and Gatekeeper SIGKILLs quarantined
binaries that are only ad-hoc signed, which cross-compiled Go binaries
are. shirabe hit this first: brew install worked but the binary died
with exit 137 until the attribute was stripped by hand. Add the same
postflight xattr hook here so casks from the next release run first
try.
2026-07-07 08:39:54 +07:00

248 行
7.5 KiB
YAML

# GoReleaser turns one tag push into everything a user might install from: raw
# archives, Linux packages (deb, rpm, apk), a multi-arch container image, and
# entries for the package managers (Homebrew, Scoop). `git tag vX.Y.Z && git
# push --tags` fans out to all of them through .github/workflows/release.yml.
#
# Publish steps that push to a repository we do not own yet (the Homebrew tap,
# the Scoop bucket) self-disable when their token is absent. A release with no
# extra secrets still produces every downloadable artifact and the container
# image; each manager lights up the moment its repository and token exist.
version: 2
project_name: kage
before:
# Only fetch modules; never `go mod tidy` during a release, the tree is kept
# tidy in CI.
hooks:
- go mod download
builds:
- id: kage
binary: kage
main: ./cmd/kage
env:
- CGO_ENABLED=0
flags:
- -trimpath
ldflags:
- -s -w
- -X github.com/tamnd/kage/cli.Version={{ .Version }}
- -X github.com/tamnd/kage/cli.Commit={{ .ShortCommit }}
- -X github.com/tamnd/kage/cli.Date={{ .CommitDate }}
mod_timestamp: "{{ .CommitTimestamp }}"
targets:
- linux_amd64
- linux_arm64
- linux_arm_7
- linux_386
- darwin_amd64
- darwin_arm64
- windows_amd64
- windows_arm64
- freebsd_amd64
- freebsd_arm64
# A second Windows build linked for the GUI subsystem (-H windowsgui). It is
# the same pure-Go kage, but a viewer packed onto it shows only its window when
# double-clicked, with no console flashing behind it. Users point `kage pack
# --base` at this to build a clean double-click Windows app. The default build
# above stays console-attached so the CLI still prints clone progress.
- id: kage-gui
binary: kage
main: ./cmd/kage
env:
- CGO_ENABLED=0
flags:
- -trimpath
ldflags:
- -s -w
- -H=windowsgui
- -X github.com/tamnd/kage/cli.Version={{ .Version }}
- -X github.com/tamnd/kage/cli.Commit={{ .ShortCommit }}
- -X github.com/tamnd/kage/cli.Date={{ .CommitDate }}
mod_timestamp: "{{ .CommitTimestamp }}"
targets:
- windows_amd64
- windows_arm64
archives:
# tar.gz everywhere except a zip on Windows. Scoped to the console build so
# this is the archive every package manager installs.
- id: default
ids:
- kage
name_template: "kage_{{ .Version }}_{{ .Os }}_{{ .Arch }}{{ with .Arm }}v{{ . }}{{ end }}"
format_overrides:
- goos: windows
formats: [zip]
files:
- LICENSE
- README.md
# A separate zip for the GUI-subsystem Windows binary, named so it cannot be
# confused with the console build. It is a base to pack against, not something
# to run directly, so no package manager points at it.
- id: windows-gui
ids:
- kage-gui
name_template: "kage_{{ .Version }}_windows-gui_{{ .Arch }}"
formats: [zip]
files:
- LICENSE
- README.md
nfpms:
# One nfpm definition emits the deb, rpm, and apk for every Linux build. kage
# is a user command, not a daemon, so there is no unit file and no
# postinstall: the package is the binary and its license. Chrome is a runtime
# dependency the user supplies (or the container image bundles).
- id: linux-packages
package_name: kage
ids:
- kage
file_name_template: "{{ .ConventionalFileName }}"
vendor: tamnd
homepage: https://github.com/tamnd/kage
maintainer: Duc-Tam Nguyen <tamnd87@gmail.com>
description: Clone any website for offline viewing, with the JavaScript stripped out.
license: MIT
formats:
- deb
- rpm
- apk
bindir: /usr/bin
section: utils
recommends:
- chromium
contents:
- src: ./LICENSE
dst: /usr/share/doc/kage/LICENSE
dockers_v2:
# One multi-platform image built with buildx. GoReleaser stages the prebuilt
# binaries under per-platform directories in the build context and the
# Dockerfile copies the right one through $TARGETPLATFORM.
- images:
- ghcr.io/tamnd/kage
tags:
- "{{ .Version }}"
- latest
dockerfile: Dockerfile
platforms:
- linux/amd64
- linux/arm64
labels:
org.opencontainers.image.title: "{{ .ProjectName }}"
org.opencontainers.image.description: "Clone any website for offline viewing, with the JavaScript stripped out"
org.opencontainers.image.url: "https://github.com/tamnd/kage"
org.opencontainers.image.source: "https://github.com/tamnd/kage"
org.opencontainers.image.version: "{{ .Version }}"
org.opencontainers.image.revision: "{{ .FullCommit }}"
org.opencontainers.image.licenses: "MIT"
homebrew_casks:
# Homebrew cask pushed to the tap repository. Self-disables until
# HOMEBREW_TAP_GITHUB_TOKEN (a PAT with write to tamnd/homebrew-tap) is set,
# so a tokenless release still writes the cask into dist for inspection.
- name: kage
ids:
- default
repository:
owner: tamnd
name: homebrew-tap
token: '{{ .Env.HOMEBREW_TAP_GITHUB_TOKEN }}'
directory: Casks
homepage: https://github.com/tamnd/kage
description: Clone any website for offline viewing, with the JavaScript stripped out
skip_upload: '{{ if index .Env "HOMEBREW_TAP_GITHUB_TOKEN" }}false{{ else }}true{{ end }}'
commit_author:
name: Duc-Tam Nguyen
email: tamnd87@gmail.com
# Homebrew quarantines cask artifacts, and Gatekeeper kills quarantined
# binaries that are only ad-hoc signed (which cross-compiled Go binaries
# are). Strip the attribute at install so the binary runs first try.
hooks:
post:
install: |
if system_command("/usr/bin/xattr", args: ["-h"]).exit_status.zero?
system_command "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "#{staged_path}/kage"]
end
scoops:
# Scoop manifest for Windows, pushed to the bucket repository. It installs the
# console build (the CLI), not the GUI base.
- ids:
- default
repository:
owner: tamnd
name: scoop-bucket
token: '{{ .Env.SCOOP_BUCKET_GITHUB_TOKEN }}'
directory: bucket
homepage: https://github.com/tamnd/kage
description: Clone any website for offline viewing, with the JavaScript stripped out
license: MIT
skip_upload: '{{ if index .Env "SCOOP_BUCKET_GITHUB_TOKEN" }}false{{ else }}true{{ end }}'
commit_author:
name: Duc-Tam Nguyen
email: tamnd87@gmail.com
checksum:
name_template: "checksums.txt"
algorithm: sha256
sboms:
# A CycloneDX SBOM per archive via syft; the release workflow installs it.
- id: archive
artifacts: archive
signs:
# Keyless cosign signature over the checksum file. It runs only on a real
# release in CI, where the workflow grants the OIDC token cosign needs.
- cmd: cosign
certificate: "${artifact}.pem"
args:
- sign-blob
- "--output-certificate=${certificate}"
- "--output-signature=${signature}"
- "${artifact}"
- "--yes"
artifacts: checksum
output: true
docker_signs:
- cmd: cosign
artifacts: manifests
args:
- sign
- "${artifact}@${digest}"
- "--yes"
changelog:
sort: asc
use: github
filters:
exclude:
- "^docs:"
- "^test:"
- "^chore:"
- "^ci:"
- Merge pull request
- Merge branch
groups:
- title: Features
regexp: '^.*?feat(\(.+\))??!?:.+$'
order: 0
- title: Fixes
regexp: '^.*?fix(\(.+\))??!?:.+$'
order: 1
- title: Other
order: 999
release:
github:
owner: tamnd
name: kage
draft: false
prerelease: auto