Add CI to style and audit the tap - #10
Merged
Merged
Conversation
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
joe4dev
marked this pull request as ready for review
September 22, 2026 15:57
2 tasks
anisaoshafi
approved these changes
Sep 23, 2026
anisaoshafi
left a comment
There was a problem hiding this comment.
Good work! Thanks for adding these guardrails 🦺
| # because `-e` would otherwise abort before the audit. | ||
| - name: Style and audit the formula | ||
| if: always() | ||
| continue-on-error: true |
There was a problem hiding this comment.
when do we change this to false? localstack/localstack-cli#57 is already approved. So the plan is to release that #57 first, then make this CI step blocking?
Member
Author
There was a problem hiding this comment.
I created a personal reminder to follow up once a new localstack-cli release ships. Refining the deprecation warning would be such a change that triggers a release.
I felt it wasn't worth triggering a dummy release.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
This tap has no CI. Content arrives two ways — release bots push generated files to
main, and people hand-edit them (#8) — and nothing checks either. The deprecatedpostflightstanza (#7) shipped that way and survived two lstk releases.localstack/lstk#511 adds a gate on the generating side, but one class of fault is invisible there: it renders the cask before the release it points at exists, so its
urls 404 and itssha256values are of locally built archives. Whether the published artifacts actually resolve and match can only be checked here.Solution
One job on
macos-latest, since casks are macOS artifacts and the runner ships Homebrew. The checkout is installed aslocalstack/tapbecause bothbrew auditand the cask cops resolve a tap name rather than a path.brew style --cask localstack/tap/lstkbrew audit --cask --online localstack/tap/lstk— fetches every url and verifies every checksum, the part lstk cannot dobrew style+brew audit --formula --onlineforlocalstack-cliMeasured on
maintodaybrew style --cask lstkbrew audit --cask --online lstkbrew style --formula localstack-clibrew audit --formula --online localstack-cliSo the cask half is green and enforced. The formula half runs with
continue-on-error: true:Formula/localstack-cli.rbis generated by localstack-cli's Homebrew Releaser, and its problems are upstream of this repo — a redundantversion, a non-standardNOASSERTIONSPDX license, and four style offences. They are reported in the log rather than blocking. Fixing them here would be overwritten by the next release; localstack/localstack-cli#57 fixes them at the source.One scheduled exception
brew styleon the cask runs with--except-cops=Cask/StanzaOrderand aTODO(localstack/lstk#512).It is green without the exception right now, because #8 hand-patched the cask. The next lstk release regenerates it from
.goreleaser.yaml, where the interim fix writes the stanza throughcustom_block— which renders it first in the file and tripsCask/StanzaOrderon every stanza after it. localstack/lstk#512 moves to thehooks.post.install_stepsform, which renders it in place; the exception comes out then.It is scoped to that one cop, so
Cask/InstallSteps— the cop that catches #7 — still fires.Dependencies
Both halves of this job carry a deliberate escape hatch, and each one closes when a fix lands elsewhere and a release regenerates the file. Merging the upstream PR alone changes nothing here.
Formula/localstack-cli.rblinting clean (verified: style, audit and audit--onlineall clean)continue-on-error: truefrom the formula step--except-cops=Cask/StanzaOrderNeither blocks merging this PR — it is useful as soon as it lands, and reports what it cannot yet enforce.
Review
Human review advised: it is this repo's first workflow, and it decides what can land in the tap.
Guards against a recurrence of #7, which #8 fixed by hand.
🤖 Generated with Claude Code