Repository navigation
feat: publish releases to WinGet and Scoop - #137
Conversation
Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/95b63705-9a9b-467c-9f21-bde357cd648d Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/91133e9a-4cd8-4ec8-84c4-a2f90a1cce21 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
|
@copilot I'd like to wait a bit, lets also pick up the issue for installation with scoop. Can you guide me on how to make that possible? |
Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/a74dac33-7d32-4a11-9537-3ac81a78b1e1 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Added Scoop support in commit What the PR now does automatically on each release:
One-time manual setup required:
Users install via: scoop bucket add scoop-bb https://github.com/vriesdemichael/scoop-bb
scoop install scoop-bb/bb |
|
@copilot Lets make the repo vriesdemichael/scoop instead of scoop-bb to enable future cli tools as well. |
Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/9ddcdb18-68ee-40b6-af26-a717fe09b537 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Updated to Placeholder {
"version": "0.0.0",
"url": "https://github.com/vriesdemichael/bitbucket-server-cli/releases/download/v0.0.0/bb_0.0.0_windows_amd64.zip",
"bin": "bb.exe"
}The CI will overwrite it with the real manifest (including proper hashes and both amd64/arm64 entries) on the first release, so the URL and hash in the placeholder don't need to be real. |
|
@copilot scoop bucket add scoop https://github.com/vriesdemichael/scoop Make it Do i also need to add a token to the repo for scoop? What permissions should it have, describe how i should make it |
Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/5979277e-1730-4643-90fb-1bcc32a49ccd Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Fixed the install commands in scoop bucket add vriesdemichael https://github.com/vriesdemichael/scoop
scoop install vriesdemichael/bbToken setup for
That's it — no other permissions needed. The token only needs to be able to push to |
…ython setup Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/6a2383ab-4e90-44a1-9028-20b8e6861b59 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Done in
|
|
Waiting for microsoft/winget-pkgs#356818 to merge so we wont trigger more PRs during the initial release |
|
@copilot I got this messsage back.
(Automated response - build 1244.) Can you give me the next steps? |
This is a known transient WinGet validation failure — no code changes are needed. The error message itself says "Another script should retry this about every 18 hours," and that's exactly what happens. WinGet's automated pipeline uses Windows Defender / SmartScreen to scan new installer URLs, and newly published GitHub releases can take a few scan cycles to be cleared. Next steps:
The |
|
@copilot Wow, okay that is incredibly unclear. So we just wait, ok |
|
@copilot The communication on winget is kind of terrible.. do the included screenshots mean it resolved itself? Or should i still take action |
Yes, it resolved itself. The winget-pkgs PR (microsoft/winget-pkgs#356818) now has both |
|
@copilot Process the pr comments posted on this branch and also take this into consideration (we had a bunch of issues with winget, this might help a little) (from an ai conversation somewhere else, translate it into instructions for yourself before you blindly take it at face value |
- Add -s -w -buildid= to Go ldflags: strips debug/DWARF tables and makes builds reproducible (same source → same hash), which prevents reputation resets in Microsoft SmartScreen/Wacatac heuristics - Add go-winres step (Windows matrix only) to embed PE metadata into the .exe before go build: company name, product name, description, copyright, and version resource — making bb.exe look like a legitimate Windows application instead of a bare Go binary - gitignore the generated rsrc_windows_*.syso files Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/e1bf7d7e-c04d-45f4-86af-9b34e8b066a0 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com>
Done in Implemented:
Not applied:
These changes take effect on the next release build. |
|
@copilot you did not mention the two comments on this pr (my guess is because you cannot read them). Here they are: The Scoop publish step embeds SCOOP_BUCKET_TOKEN directly in the git clone URL. If git clone/git push fails, git error output can include the full remote URL, which risks leaking the token in logs (masking is not guaranteed for all token formats). Prefer cloning without credentials and only supplying the token for the push (or configuring a credential helper / url.insteadOf) so the token is never part of a printed URL. https://github.com/apps/copilot-pull-request-reviewer AI scoop-release relies on python being available on ubuntu-latest, but this job doesn’t set it up (unlike the other release jobs earlier in this workflow). Add an explicit actions/setup-python@v5 step (and pin/choose a version) to avoid breakage if the runner image changes. Are those taken into account as well? |
Yes, both were addressed in commit
|
Adds automated publishing of the CLI to Windows package managers (WinGet and Scoop) as part of the release workflow, and documents the new installation paths for Windows users.
Changes Made
winget-releasejob to.github/workflows/release.ymlusingvedantmgoyal9/winget-releaser@v2with identifiervriesdemichael.bbscoop-releasejob to.github/workflows/release.ymlthat downloadssha256sums.txtfrom the GitHub release, generates abb.jsonScoop manifest (amd64 + arm64, withautoupdateURLs), and pushes it tovriesdemichael/scoopusingSCOOP_BUCKET_TOKENactions/setup-python@v5step to thescoop-releasejobREADME.mdanddocs/site/installation-and-quickstart.mdwith WinGet and Scoop install commands:LICENSEfile (Apache 2.0, copyright Michael de Vries); Scoop manifestlicensefield set toApache-2.0-s -w -buildid=to Go ldflags to strip debug/DWARF tables and produce reproducible builds, reducing Windows Defender/SmartScreen heuristic false-positive risk. Added a Windows-onlygo-winresstep that embeds a proper PE VERSIONINFO resource (product name, file description, copyright, version) intobb.exebefore compilation, making it identifiable as a legitimate Windows application rather than a bare Go binary.