Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 99 additions & 0 deletions .github/workflows/publish-chocolatey.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,99 @@
name: Publish to Chocolatey

# Manual only: run it by hand (Actions tab, or
# gh workflow run publish-chocolatey.yml -f version=1.85.13
# ) for an already-released version. It is deliberately NOT wired into
# release-manual.yml: every pushed version sits in Chocolatey moderation for a
# long time, so we choose which releases to submit rather than pushing each one.
#
# The package templates are taken from the ref this workflow runs on (main), not
# from the release tag, so packaging fixes apply to versions released before them.

on:
workflow_dispatch:
inputs:
version:
description: 'Released version to package (e.g. 1.85.13)'
required: true
type: string

jobs:
publish-chocolatey:
name: Publish to Chocolatey
runs-on: windows-latest

steps:
- uses: actions/checkout@v4

- name: Download Windows binary from GitHub release
id: download
shell: pwsh
run: |
$version = '${{ inputs.version }}'.TrimStart('v')
$url = "https://github.com/TimelordUK/sql-cli/releases/download/v$version/sql-cli-windows-x64.exe"
$target = Join-Path $env:RUNNER_TEMP 'sql-cli-windows-x64.exe'
Write-Host "Fetching $url"
# Retry a few times — the asset may take a few seconds to appear after release create.
$ok = $false
for ($i = 0; $i -lt 10; $i++) {
try {
Invoke-WebRequest -Uri $url -OutFile $target -UseBasicParsing
$ok = $true
break
} catch {
Write-Host "Attempt $($i+1) failed: $($_.Exception.Message). Retrying in 6s..."
Start-Sleep -Seconds 6
}
}
if (-not $ok) { throw "Could not download $url after retries" }
$hash = (Get-FileHash $target -Algorithm SHA256).Hash
Write-Host "SHA256: $hash"
"version=$version" | Out-File -FilePath $env:GITHUB_OUTPUT -Append
"checksum=$hash" | Out-File -FilePath $env:GITHUB_OUTPUT -Append

- name: Substitute version and checksum into templates
shell: pwsh
run: |
$version = '${{ steps.download.outputs.version }}'
$checksum = '${{ steps.download.outputs.checksum }}'

(Get-Content chocolatey/sql-cli.nuspec.template -Raw) `
-replace '__VERSION__', $version `
| Set-Content chocolatey/sql-cli.nuspec -NoNewline

(Get-Content chocolatey/tools/chocolateyInstall.ps1.template -Raw) `
-replace '__VERSION__', $version `
-replace '__CHECKSUM__', $checksum `
| Set-Content chocolatey/tools/chocolateyInstall.ps1 -NoNewline

Remove-Item chocolatey/sql-cli.nuspec.template
Remove-Item chocolatey/tools/chocolateyInstall.ps1.template

Write-Host '--- nuspec ---'
Get-Content chocolatey/sql-cli.nuspec
Write-Host '--- chocolateyInstall.ps1 ---'
Get-Content chocolatey/tools/chocolateyInstall.ps1

- name: choco pack
shell: pwsh
working-directory: chocolatey
run: choco pack sql-cli.nuspec

- name: choco push
shell: pwsh
working-directory: chocolatey
env:
CHOCOLATEY_API_KEY: ${{ secrets.CHOCOLATEY_API_KEY }}
run: |
$nupkg = Get-ChildItem -Filter "sql-cli.*.nupkg" | Select-Object -First 1
if (-not $nupkg) { throw "No .nupkg produced by choco pack" }
Write-Host "Pushing $($nupkg.Name)"
choco push $nupkg.FullName --source https://push.chocolatey.org/ --api-key "$env:CHOCOLATEY_API_KEY"

- name: Upload .nupkg artifact
if: always()
uses: actions/upload-artifact@v4
with:
name: sql-cli-chocolatey-nupkg
path: chocolatey/*.nupkg
if-no-files-found: warn
89 changes: 1 addition & 88 deletions .github/workflows/release-manual.yml
Original file line number Diff line number Diff line change
Expand Up @@ -363,91 +363,4 @@ jobs:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

# TEMPORARILY DISABLED (2026-06-07): Chocolatey publish is on hold.
# The initial package submission has been pending moderation on chocolatey.org
# for weeks with no response; the version appears locked while in review, so new
# build pushes are rejected. Re-enable this job (uncomment) once the package is
# approved/signed off by Chocolatey moderation.
#
# publish-chocolatey:
# name: Publish to Chocolatey
# needs: [prepare-release, release]
# runs-on: windows-latest
# if: ${{ !cancelled() && needs.release.result == 'success' }}
#
# steps:
# - uses: actions/checkout@v4
# with:
# ref: v${{ needs.prepare-release.outputs.new_version }}
#
# - name: Download Windows binary from GitHub release
# id: download
# shell: pwsh
# run: |
# $version = '${{ needs.prepare-release.outputs.new_version }}'
# $url = "https://github.com/TimelordUK/sql-cli/releases/download/v$version/sql-cli-windows-x64.exe"
# $target = Join-Path $env:RUNNER_TEMP 'sql-cli-windows-x64.exe'
# Write-Host "Fetching $url"
# # Retry a few times — the asset may take a few seconds to appear after release create.
# $ok = $false
# for ($i = 0; $i -lt 10; $i++) {
# try {
# Invoke-WebRequest -Uri $url -OutFile $target -UseBasicParsing
# $ok = $true
# break
# } catch {
# Write-Host "Attempt $($i+1) failed: $($_.Exception.Message). Retrying in 6s..."
# Start-Sleep -Seconds 6
# }
# }
# if (-not $ok) { throw "Could not download $url after retries" }
# $hash = (Get-FileHash $target -Algorithm SHA256).Hash
# Write-Host "SHA256: $hash"
# "checksum=$hash" | Out-File -FilePath $env:GITHUB_OUTPUT -Append
#
# - name: Substitute version and checksum into templates
# shell: pwsh
# run: |
# $version = '${{ needs.prepare-release.outputs.new_version }}'
# $checksum = '${{ steps.download.outputs.checksum }}'
#
# (Get-Content chocolatey/sql-cli.nuspec.template -Raw) `
# -replace '__VERSION__', $version `
# | Set-Content chocolatey/sql-cli.nuspec -NoNewline
#
# (Get-Content chocolatey/tools/chocolateyInstall.ps1.template -Raw) `
# -replace '__VERSION__', $version `
# -replace '__CHECKSUM__', $checksum `
# | Set-Content chocolatey/tools/chocolateyInstall.ps1 -NoNewline
#
# Remove-Item chocolatey/sql-cli.nuspec.template
# Remove-Item chocolatey/tools/chocolateyInstall.ps1.template
#
# Write-Host '--- nuspec ---'
# Get-Content chocolatey/sql-cli.nuspec
# Write-Host '--- chocolateyInstall.ps1 ---'
# Get-Content chocolatey/tools/chocolateyInstall.ps1
#
# - name: choco pack
# shell: pwsh
# working-directory: chocolatey
# run: choco pack sql-cli.nuspec
#
# - name: choco push
# shell: pwsh
# working-directory: chocolatey
# env:
# CHOCOLATEY_API_KEY: ${{ secrets.CHOCOLATEY_API_KEY }}
# run: |
# $nupkg = Get-ChildItem -Filter "sql-cli.*.nupkg" | Select-Object -First 1
# if (-not $nupkg) { throw "No .nupkg produced by choco pack" }
# Write-Host "Pushing $($nupkg.Name)"
# choco push $nupkg.FullName --source https://push.chocolatey.org/ --api-key "$env:CHOCOLATEY_API_KEY"
#
# - name: Upload .nupkg artifact
# if: always()
# uses: actions/upload-artifact@v4
# with:
# name: sql-cli-chocolatey-nupkg
# path: chocolatey/*.nupkg
# if-no-files-found: warn
# Chocolatey is published separately and by hand: see publish-chocolatey.yml.
29 changes: 17 additions & 12 deletions chocolatey/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Chocolatey packaging

This folder contains the template files used by the release workflow to publish
This folder contains the template files used by `publish-chocolatey.yml` to publish
sql-cli to the [Chocolatey Community Repository](https://community.chocolatey.org/).

## Layout
Expand All @@ -9,32 +9,37 @@ sql-cli to the [Chocolatey Community Repository](https://community.chocolatey.or
- `tools/chocolateyInstall.ps1.template` — downloads the Windows binary from the matching
GitHub release and verifies its SHA256. `__VERSION__` and `__CHECKSUM__` are replaced
at pack time.
- `tools/VERIFICATION.txt` — instructions for the Chocolatey moderation team to verify
the package contents against the published source.
- `tools/LICENSE.txt` — a copy of the upstream MIT license (required by Chocolatey
moderation for binary packages).

No `VERIFICATION.txt` / `LICENSE.txt`: the package downloads the binary rather than
embedding it, and the Chocolatey moderators asked for both files to be removed. The
nuspec's `packageSourceUrl` points moderators at this folder instead.

Chocolatey auto-shims any `.exe` placed in `tools/`, so after install the binary is
available on `PATH` as `sql-cli`.

## Publishing

Publishing is automated in `.github/workflows/release-manual.yml`. The workflow runs
after the GitHub release is created — at that point the Windows binary asset is
available at a stable URL, so the workflow:
Publishing is **manual**, and separate from the release workflow. crates.io gets every
release; Chocolatey gets only the versions we choose to submit, because each pushed
version sits in moderation for a long time.

Once a GitHub release exists, run `.github/workflows/publish-chocolatey.yml` with its
version (Actions tab, or `gh workflow run publish-chocolatey.yml -f version=1.85.13`).
It:

1. Downloads `sql-cli-windows-x64.exe` from the release.
1. Downloads `sql-cli-windows-x64.exe` from that release.
2. Computes its SHA256.
3. Substitutes `__VERSION__` and `__CHECKSUM__` into the templates.
4. Runs `choco pack` and `choco push`.
3. Substitutes `__VERSION__` and `__CHECKSUM__` into the templates (taken from `main`,
so packaging fixes apply to older releases too).
4. Runs `choco pack` and `choco push`, and uploads the `.nupkg` as a build artifact.

## One-time setup

1. Create a Chocolatey account at <https://community.chocolatey.org/account/Register>.
2. Generate an API key at <https://community.chocolatey.org/account>.
3. Add it as a GitHub repo secret named `CHOCOLATEY_API_KEY`.
4. The **first** submission of a brand-new package id goes through manual moderator
review (typically a few days). Subsequent versions normally auto-pass.
review, which can take weeks to months.

## Testing locally

Expand Down
1 change: 1 addition & 0 deletions chocolatey/sql-cli.nuspec.template
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
<authors>TimelordUK</authors>
<owners>TimelordUK</owners>
<projectUrl>https://github.com/TimelordUK/sql-cli</projectUrl>
<packageSourceUrl>https://github.com/TimelordUK/sql-cli/tree/main/chocolatey</packageSourceUrl>
<projectSourceUrl>https://github.com/TimelordUK/sql-cli</projectSourceUrl>
<docsUrl>https://github.com/TimelordUK/sql-cli/blob/main/README.md</docsUrl>
<bugTrackerUrl>https://github.com/TimelordUK/sql-cli/issues</bugTrackerUrl>
Expand Down
23 changes: 0 additions & 23 deletions chocolatey/tools/LICENSE.txt

This file was deleted.

21 changes: 0 additions & 21 deletions chocolatey/tools/VERIFICATION.txt

This file was deleted.

Loading