feat: Homebrew formula and Ubuntu/Debian packages with a signed APT repository - #30
Merged
Merged
Conversation
…epository - GoReleaser builds a lintian-clean .deb (amd64, arm64) with a dotsync(1) man page, a Debian changelog and SBOMs; packages are checksummed and attested like the archives. - The release workflow publishes a Homebrew formula (prebuilt, checksum-pinned archives) to the tap in vars.HOMEBREW_TAP, and the docs workflow serves a signed APT repository at /apt/ built from the latest release, after verifying checksums and provenance. - dotsync detects Homebrew and apt installs: `update` defers to the package manager, the background agent runs the package's stable path, and doctor flags a stale ~/.local/bin copy. - CI lints the .deb, installs it with apt from a throwaway signed repository on Ubuntu 22.04/24.04 and Debian 12/13, and installs, tests and audits the formula with Homebrew on macOS and Linux. - The man page is generated from the command table, so it can't drift from `help`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Resolves conflicts with the docs redesign by re-applying the Homebrew/apt additions to the new pages, and switches the man page to flagSetHook so it lists flags exactly like the generated docs reference. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…cOS) Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
pungoyal
marked this pull request as ready for review
September 21, 2026 14:32
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Adds two new ways to install dotsync, each kept up to date by its package manager:
brew install pungoyal/tap/dotsync. I used a formula rather than a cask. Casks are meant for macOS apps, and they quarantine what they download, so Gatekeeper would block our binary because it isn't notarized. Formulae also work on Linux. GoReleaser has deprecated itsbrewssection, sopackaging/homebrew/formula.shgenerates the formula from the release'schecksums.txtinstead. The release workflow then pushes it to the tap named invars.HOMEBREW_TAP..deb(amd64 and arm64). It's checksummed, attested and covered by an SBOM, the same as the archives. The docs workflow builds a signed APT repository from the latest release, served athttps://pungoyal.github.io/dotsync/apt/. Before building it, it checks each package's checksum and build provenance. The docs describe adeb822source that usesSigned-By.What else changed to make the packages work:
internal/dotsync/packaged.go):dotsync updateno longer replaces a binary that Homebrew or apt owns. It tells you the package manager's command instead.$(brew --prefix)/bin/dotsyncor/usr/bin/dotsync) instead of a copy in~/.local/bin, so upgrades reach it.doctorwarns about a leftover copy in~/.local/bin.dpkg-query, not dpkg's internal database.dotsync(1)man page, generated from the command table and each command's flags, so it can't drift fromdotsync help. The man page ships in the archives, the.deband the formula..debpasses lintian with no warnings, even at pedantic level:CHANGELOG.mdgit (>= 1:2.20)X.Y.Z~snapshot.<commit>, a Debian "native" version like a real release's, so CI lints exactly what a release produces.Setup needed from a maintainer (both optional; without them releases still ship the
.debs)pungoyal/homebrew-tapand set the variableHOMEBREW_TAP=pungoyal/homebrew-tap. Then either install the release GitHub App on the tap, or addsecrets.HOMEBREW_TAP_TOKEN.secrets.APT_SIGNING_KEY.CONTRIBUTING.mdhas the steps. The key doesn't expire, on purpose: an expired APT key breaksapt updatefor every user.How was this tested?
TestPackagedAt,TestUpdateDefersToPackageManager,TestManPagewebsite/src/content/docs/updated (installation, commands, files, uninstall, verifying releases); the site builds with all links validChecked locally:
.deb: lintian at>=pedanticwith--fail-on warningpasses. Installing and removing with apt works on Ubuntu 22.04 and 24.04 and Debian 12 and 13.apt installworks, and a wrong key is refused.brew installworksbrew testpasses; it runs a full init → add → push round tripbrew audit --strictandbrew styleare cleandotsync updatedefers tobrew upgradeCI now repeats these checks on every PR: new
debandhomebrew(macOS and Linux) jobs, both required byci ok.🤖 Generated with Claude Code