Skip to content

Commit b164f07

Browse files
committed
Migrate goreleaser off deprecated brews and dockers
`goreleaser check` fails on the v2.16 `brews` deprecation, and `dockers`/ `docker_manifests` are being phased out in favor of `dockers_v2`. - Replace `brews` with `homebrew_casks` (binaries + completions, plus a post-install hook to clear the macOS quarantine attribute since the binaries are GPG-signed but not Apple-notarized). - Replace `dockers` with `dockers_v2`, preserving the plain single-arch linux/amd64 image and its labels (sbom/provenance left off to match the previous output). - Update docker/alpine to COPY from $TARGETPLATFORM, as dockers_v2 stages artifacts per-platform. - Set up Docker Buildx in the release workflow, which dockers_v2 requires. - Bump goreleaser-action to v7.2.3, pinned by commit SHA, in the build and release-test workflows.
1 parent 4f4dd17 commit b164f07

5 files changed

Lines changed: 47 additions & 30 deletions

File tree

‎.github/workflows/build.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
with:
3434
path: ./src/github.com/${{ github.repository }}
3535
- name: GoReleaser Check
36-
uses: goreleaser/goreleaser-action@v6
36+
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
3737
with:
3838
version: latest
3939
args: check

‎.github/workflows/release-tests.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ jobs:
2424
with:
2525
path: ./src/github.com/${{ github.repository }}
2626
- name: GoReleaser Action
27-
uses: goreleaser/goreleaser-action@v6
27+
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
2828
with:
2929
version: latest
3030
args: release --snapshot --skip=publish,sign

‎.github/workflows/release.yaml‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,10 @@ jobs:
3131
ref: "master"
3232
# include tags so we can determine new version
3333
fetch-depth: 0
34+
- name: Set up Docker Buildx
35+
# dockers_v2 builds via `docker buildx build`; goreleaser expects the
36+
# docker-container driver, which this action configures by default
37+
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
3438
- name: Update alpine image
3539
run: docker pull alpine
3640
- name: Install Doppler CLI

‎.goreleaser.yml‎

Lines changed: 38 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -105,45 +105,56 @@ changelog:
105105
- Merge pull request
106106
- Merge branch
107107

108-
dockers:
108+
dockers_v2:
109109
- dockerfile: docker/alpine
110-
goos: linux
111-
goarch: amd64
112110
ids:
113111
- doppler
114-
image_templates:
115-
- "dopplerhq/cli:{{ .Version }}" # Ex: 1.4.2
116-
- "dopplerhq/cli:{{ .Major }}.{{ .Minor }}" # Ex: 1.4
117-
- "dopplerhq/cli:{{ .Major }}" # Ex: 1
118-
- "dopplerhq/cli:latest"
119-
- "gcr.io/dopplerhq/cli:{{ .Version }}" # Ex: 1.4.2
120-
- "gcr.io/dopplerhq/cli:{{ .Major }}.{{ .Minor }}" # Ex: 1.4
121-
- "gcr.io/dopplerhq/cli:{{ .Major }}" # Ex: 1
122-
- "gcr.io/dopplerhq/cli:latest"
123-
build_flag_templates:
124-
- "--label=org.label-schema.schema-version=1.0"
125-
- "--label=org.label-schema.version={{.Version}}"
126-
- "--label=org.label-schema.name={{.ProjectName}}"
127-
- "--platform=linux/amd64"
128-
129-
brews:
112+
platforms:
113+
- linux/amd64
114+
images:
115+
- dopplerhq/cli
116+
- gcr.io/dopplerhq/cli
117+
tags:
118+
- "{{ .Version }}" # Ex: 1.4.2
119+
- "{{ .Major }}.{{ .Minor }}" # Ex: 1.4
120+
- "{{ .Major }}" # Ex: 1
121+
- "latest"
122+
labels:
123+
org.label-schema.schema-version: "1.0"
124+
org.label-schema.version: "{{ .Version }}"
125+
org.label-schema.name: "{{ .ProjectName }}"
126+
sbom: false
127+
flags:
128+
- "--provenance=false"
129+
130+
homebrew_casks:
130131
- name: doppler
131132
repository:
132133
owner: DopplerHQ
133134
name: homebrew-doppler
134135
commit_author:
135136
name: "Doppler Bot"
136137
email: bot@doppler.com
137-
directory: Formula
138138
homepage: "https://doppler.com"
139139
description: "The official Doppler CLI for managing your secrets"
140-
install: |-
141-
bin.install "doppler"
142-
bash_completion.install "completions/doppler.bash" => "doppler"
143-
zsh_completion.install "completions/doppler.zsh" => "_doppler"
144-
fish_completion.install "completions/doppler.fish"
145-
test: |
146-
system "#{bin}/doppler --version"
140+
# homepage (doppler.com) differs from the release download domain
141+
# (github.com), so mark the URL verified to satisfy `brew audit`
142+
url:
143+
verified: github.com/DopplerHQ/cli
144+
binaries:
145+
- doppler
146+
completions:
147+
bash: completions/doppler.bash
148+
zsh: completions/doppler.zsh
149+
fish: completions/doppler.fish
150+
# binaries are GPG-signed but not Apple-notarized, so strip the Gatekeeper
151+
# quarantine attribute on macOS to keep `brew install` working
152+
hooks:
153+
post:
154+
install: |
155+
if OS.mac?
156+
system_command "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "#{staged_path}/doppler"]
157+
end
147158
148159
scoops:
149160
- repository:

‎docker/alpine‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,5 +4,7 @@ RUN apk add --no-cache tini
44
# Update OpenSSL to address CVE because `alpine` isn't updated yet
55
RUN apk update && apk upgrade --no-cache libcrypto3 libssl3
66

7-
COPY doppler /bin/doppler
7+
# dockers_v2 stages artifacts under $TARGETPLATFORM/ in the build context
8+
ARG TARGETPLATFORM
9+
COPY $TARGETPLATFORM/doppler /bin/doppler
810
ENTRYPOINT ["/sbin/tini", "--", "/bin/doppler"]

0 commit comments

Comments
 (0)