From bec2e55d0a08ced011c8892befb08340ab389128 Mon Sep 17 00:00:00 2001 From: TimelordUK Date: Tue, 29 Sep 2026 18:20:49 +0100 Subject: [PATCH] chore(choco): address moderator feedback, publish manually - Remove tools/VERIFICATION.txt and tools/LICENSE.txt (moderator request; the package downloads the binary rather than embedding it). - Add packageSourceUrl pointing at the chocolatey/ folder. - Move the publish job out of release-manual.yml into a manual-only publish-chocolatey.yml (workflow_dispatch with a version input). crates.io keeps publishing every release; Chocolatey gets the versions we pick, since each submission waits a long time in moderation. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/publish-chocolatey.yml | 99 ++++++++++++++++++++++++ .github/workflows/release-manual.yml | 89 +-------------------- chocolatey/README.md | 29 ++++--- chocolatey/sql-cli.nuspec.template | 1 + chocolatey/tools/LICENSE.txt | 23 ------ chocolatey/tools/VERIFICATION.txt | 21 ----- 6 files changed, 118 insertions(+), 144 deletions(-) create mode 100644 .github/workflows/publish-chocolatey.yml delete mode 100644 chocolatey/tools/LICENSE.txt delete mode 100644 chocolatey/tools/VERIFICATION.txt diff --git a/.github/workflows/publish-chocolatey.yml b/.github/workflows/publish-chocolatey.yml new file mode 100644 index 00000000..d96e1e87 --- /dev/null +++ b/.github/workflows/publish-chocolatey.yml @@ -0,0 +1,99 @@ +name: Publish to Chocolatey + +# Manual only: run it by hand (Actions tab, or +# gh workflow run publish-chocolatey.yml -f version=1.85.13 +# ) for an already-released version. It is deliberately NOT wired into +# release-manual.yml: every pushed version sits in Chocolatey moderation for a +# long time, so we choose which releases to submit rather than pushing each one. +# +# The package templates are taken from the ref this workflow runs on (main), not +# from the release tag, so packaging fixes apply to versions released before them. + +on: + workflow_dispatch: + inputs: + version: + description: 'Released version to package (e.g. 1.85.13)' + required: true + type: string + +jobs: + publish-chocolatey: + name: Publish to Chocolatey + runs-on: windows-latest + + steps: + - uses: actions/checkout@v4 + + - name: Download Windows binary from GitHub release + id: download + shell: pwsh + run: | + $version = '${{ inputs.version }}'.TrimStart('v') + $url = "https://github.com/TimelordUK/sql-cli/releases/download/v$version/sql-cli-windows-x64.exe" + $target = Join-Path $env:RUNNER_TEMP 'sql-cli-windows-x64.exe' + Write-Host "Fetching $url" + # Retry a few times — the asset may take a few seconds to appear after release create. + $ok = $false + for ($i = 0; $i -lt 10; $i++) { + try { + Invoke-WebRequest -Uri $url -OutFile $target -UseBasicParsing + $ok = $true + break + } catch { + Write-Host "Attempt $($i+1) failed: $($_.Exception.Message). Retrying in 6s..." + Start-Sleep -Seconds 6 + } + } + if (-not $ok) { throw "Could not download $url after retries" } + $hash = (Get-FileHash $target -Algorithm SHA256).Hash + Write-Host "SHA256: $hash" + "version=$version" | Out-File -FilePath $env:GITHUB_OUTPUT -Append + "checksum=$hash" | Out-File -FilePath $env:GITHUB_OUTPUT -Append + + - name: Substitute version and checksum into templates + shell: pwsh + run: | + $version = '${{ steps.download.outputs.version }}' + $checksum = '${{ steps.download.outputs.checksum }}' + + (Get-Content chocolatey/sql-cli.nuspec.template -Raw) ` + -replace '__VERSION__', $version ` + | Set-Content chocolatey/sql-cli.nuspec -NoNewline + + (Get-Content chocolatey/tools/chocolateyInstall.ps1.template -Raw) ` + -replace '__VERSION__', $version ` + -replace '__CHECKSUM__', $checksum ` + | Set-Content chocolatey/tools/chocolateyInstall.ps1 -NoNewline + + Remove-Item chocolatey/sql-cli.nuspec.template + Remove-Item chocolatey/tools/chocolateyInstall.ps1.template + + Write-Host '--- nuspec ---' + Get-Content chocolatey/sql-cli.nuspec + Write-Host '--- chocolateyInstall.ps1 ---' + Get-Content chocolatey/tools/chocolateyInstall.ps1 + + - name: choco pack + shell: pwsh + working-directory: chocolatey + run: choco pack sql-cli.nuspec + + - name: choco push + shell: pwsh + working-directory: chocolatey + env: + CHOCOLATEY_API_KEY: ${{ secrets.CHOCOLATEY_API_KEY }} + run: | + $nupkg = Get-ChildItem -Filter "sql-cli.*.nupkg" | Select-Object -First 1 + if (-not $nupkg) { throw "No .nupkg produced by choco pack" } + Write-Host "Pushing $($nupkg.Name)" + choco push $nupkg.FullName --source https://push.chocolatey.org/ --api-key "$env:CHOCOLATEY_API_KEY" + + - name: Upload .nupkg artifact + if: always() + uses: actions/upload-artifact@v4 + with: + name: sql-cli-chocolatey-nupkg + path: chocolatey/*.nupkg + if-no-files-found: warn diff --git a/.github/workflows/release-manual.yml b/.github/workflows/release-manual.yml index 1f74a311..78832d8d 100644 --- a/.github/workflows/release-manual.yml +++ b/.github/workflows/release-manual.yml @@ -363,91 +363,4 @@ jobs: env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# TEMPORARILY DISABLED (2026-06-07): Chocolatey publish is on hold. -# The initial package submission has been pending moderation on chocolatey.org -# for weeks with no response; the version appears locked while in review, so new -# build pushes are rejected. Re-enable this job (uncomment) once the package is -# approved/signed off by Chocolatey moderation. -# -# publish-chocolatey: -# name: Publish to Chocolatey -# needs: [prepare-release, release] -# runs-on: windows-latest -# if: ${{ !cancelled() && needs.release.result == 'success' }} -# -# steps: -# - uses: actions/checkout@v4 -# with: -# ref: v${{ needs.prepare-release.outputs.new_version }} -# -# - name: Download Windows binary from GitHub release -# id: download -# shell: pwsh -# run: | -# $version = '${{ needs.prepare-release.outputs.new_version }}' -# $url = "https://github.com/TimelordUK/sql-cli/releases/download/v$version/sql-cli-windows-x64.exe" -# $target = Join-Path $env:RUNNER_TEMP 'sql-cli-windows-x64.exe' -# Write-Host "Fetching $url" -# # Retry a few times — the asset may take a few seconds to appear after release create. -# $ok = $false -# for ($i = 0; $i -lt 10; $i++) { -# try { -# Invoke-WebRequest -Uri $url -OutFile $target -UseBasicParsing -# $ok = $true -# break -# } catch { -# Write-Host "Attempt $($i+1) failed: $($_.Exception.Message). Retrying in 6s..." -# Start-Sleep -Seconds 6 -# } -# } -# if (-not $ok) { throw "Could not download $url after retries" } -# $hash = (Get-FileHash $target -Algorithm SHA256).Hash -# Write-Host "SHA256: $hash" -# "checksum=$hash" | Out-File -FilePath $env:GITHUB_OUTPUT -Append -# -# - name: Substitute version and checksum into templates -# shell: pwsh -# run: | -# $version = '${{ needs.prepare-release.outputs.new_version }}' -# $checksum = '${{ steps.download.outputs.checksum }}' -# -# (Get-Content chocolatey/sql-cli.nuspec.template -Raw) ` -# -replace '__VERSION__', $version ` -# | Set-Content chocolatey/sql-cli.nuspec -NoNewline -# -# (Get-Content chocolatey/tools/chocolateyInstall.ps1.template -Raw) ` -# -replace '__VERSION__', $version ` -# -replace '__CHECKSUM__', $checksum ` -# | Set-Content chocolatey/tools/chocolateyInstall.ps1 -NoNewline -# -# Remove-Item chocolatey/sql-cli.nuspec.template -# Remove-Item chocolatey/tools/chocolateyInstall.ps1.template -# -# Write-Host '--- nuspec ---' -# Get-Content chocolatey/sql-cli.nuspec -# Write-Host '--- chocolateyInstall.ps1 ---' -# Get-Content chocolatey/tools/chocolateyInstall.ps1 -# -# - name: choco pack -# shell: pwsh -# working-directory: chocolatey -# run: choco pack sql-cli.nuspec -# -# - name: choco push -# shell: pwsh -# working-directory: chocolatey -# env: -# CHOCOLATEY_API_KEY: ${{ secrets.CHOCOLATEY_API_KEY }} -# run: | -# $nupkg = Get-ChildItem -Filter "sql-cli.*.nupkg" | Select-Object -First 1 -# if (-not $nupkg) { throw "No .nupkg produced by choco pack" } -# Write-Host "Pushing $($nupkg.Name)" -# choco push $nupkg.FullName --source https://push.chocolatey.org/ --api-key "$env:CHOCOLATEY_API_KEY" -# -# - name: Upload .nupkg artifact -# if: always() -# uses: actions/upload-artifact@v4 -# with: -# name: sql-cli-chocolatey-nupkg -# path: chocolatey/*.nupkg -# if-no-files-found: warn \ No newline at end of file +# Chocolatey is published separately and by hand: see publish-chocolatey.yml. diff --git a/chocolatey/README.md b/chocolatey/README.md index 84e29ce4..e5e10379 100644 --- a/chocolatey/README.md +++ b/chocolatey/README.md @@ -1,6 +1,6 @@ # Chocolatey packaging -This folder contains the template files used by the release workflow to publish +This folder contains the template files used by `publish-chocolatey.yml` to publish sql-cli to the [Chocolatey Community Repository](https://community.chocolatey.org/). ## Layout @@ -9,24 +9,29 @@ sql-cli to the [Chocolatey Community Repository](https://community.chocolatey.or - `tools/chocolateyInstall.ps1.template` — downloads the Windows binary from the matching GitHub release and verifies its SHA256. `__VERSION__` and `__CHECKSUM__` are replaced at pack time. -- `tools/VERIFICATION.txt` — instructions for the Chocolatey moderation team to verify - the package contents against the published source. -- `tools/LICENSE.txt` — a copy of the upstream MIT license (required by Chocolatey - moderation for binary packages). + +No `VERIFICATION.txt` / `LICENSE.txt`: the package downloads the binary rather than +embedding it, and the Chocolatey moderators asked for both files to be removed. The +nuspec's `packageSourceUrl` points moderators at this folder instead. Chocolatey auto-shims any `.exe` placed in `tools/`, so after install the binary is available on `PATH` as `sql-cli`. ## Publishing -Publishing is automated in `.github/workflows/release-manual.yml`. The workflow runs -after the GitHub release is created — at that point the Windows binary asset is -available at a stable URL, so the workflow: +Publishing is **manual**, and separate from the release workflow. crates.io gets every +release; Chocolatey gets only the versions we choose to submit, because each pushed +version sits in moderation for a long time. + +Once a GitHub release exists, run `.github/workflows/publish-chocolatey.yml` with its +version (Actions tab, or `gh workflow run publish-chocolatey.yml -f version=1.85.13`). +It: -1. Downloads `sql-cli-windows-x64.exe` from the release. +1. Downloads `sql-cli-windows-x64.exe` from that release. 2. Computes its SHA256. -3. Substitutes `__VERSION__` and `__CHECKSUM__` into the templates. -4. Runs `choco pack` and `choco push`. +3. Substitutes `__VERSION__` and `__CHECKSUM__` into the templates (taken from `main`, + so packaging fixes apply to older releases too). +4. Runs `choco pack` and `choco push`, and uploads the `.nupkg` as a build artifact. ## One-time setup @@ -34,7 +39,7 @@ available at a stable URL, so the workflow: 2. Generate an API key at . 3. Add it as a GitHub repo secret named `CHOCOLATEY_API_KEY`. 4. The **first** submission of a brand-new package id goes through manual moderator - review (typically a few days). Subsequent versions normally auto-pass. + review, which can take weeks to months. ## Testing locally diff --git a/chocolatey/sql-cli.nuspec.template b/chocolatey/sql-cli.nuspec.template index 69c29c2e..e1f4500f 100644 --- a/chocolatey/sql-cli.nuspec.template +++ b/chocolatey/sql-cli.nuspec.template @@ -7,6 +7,7 @@ TimelordUK TimelordUK https://github.com/TimelordUK/sql-cli + https://github.com/TimelordUK/sql-cli/tree/main/chocolatey https://github.com/TimelordUK/sql-cli https://github.com/TimelordUK/sql-cli/blob/main/README.md https://github.com/TimelordUK/sql-cli/issues diff --git a/chocolatey/tools/LICENSE.txt b/chocolatey/tools/LICENSE.txt deleted file mode 100644 index beb72157..00000000 --- a/chocolatey/tools/LICENSE.txt +++ /dev/null @@ -1,23 +0,0 @@ -From: https://github.com/TimelordUK/sql-cli/blob/main/LICENSE - -MIT License - -Copyright (c) 2024 SQL CLI Project - -Permission is hereby granted, free of charge, to any person obtaining a copy -of this software and associated documentation files (the "Software"), to deal -in the Software without restriction, including without limitation the rights -to use, copy, modify, merge, publish, distribute, sublicense, and/or sell -copies of the Software, and to permit persons to whom the Software is -furnished to do so, subject to the following conditions: - -The above copyright notice and this permission notice shall be included in all -copies or substantial portions of the Software. - -THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR -IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, -FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE -AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER -LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, -OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE -SOFTWARE. diff --git a/chocolatey/tools/VERIFICATION.txt b/chocolatey/tools/VERIFICATION.txt deleted file mode 100644 index e3190a4f..00000000 --- a/chocolatey/tools/VERIFICATION.txt +++ /dev/null @@ -1,21 +0,0 @@ -VERIFICATION - -sql-cli is an open-source Rust application published by TimelordUK. - -Source: https://github.com/TimelordUK/sql-cli -Release page: https://github.com/TimelordUK/sql-cli/releases -License: MIT (see LICENSE.txt in this package, or the LICENSE file in - the source repository) - -This Chocolatey package downloads the Windows x64 binary from the matching -GitHub release tag. The binary is built by the project's GitHub Actions -release workflow (.github/workflows/release-manual.yml) from a tagged -commit; the workflow output is what is published to the GitHub release. - -To verify the file integrity, compare the SHA256 in `chocolateyInstall.ps1` -against the SHA256 of the downloaded binary: - - Get-FileHash sql-cli.exe -Algorithm SHA256 - -The same checksum can be re-computed from the public asset URL embedded in -chocolateyInstall.ps1.