Skip to content

Use hooks.post.install_steps for the cask quarantine step - #512

Draft
joe4dev wants to merge 2 commits into
mainfrom
devx-1124-cask-install-steps
Draft

joe4dev wants to merge 2 commits into
mainfrom
devx-1124-cask-install-steps

Conversation

@joe4dev

@joe4dev joe4dev commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Warning

Blocked by upstream — do not merge yet.

hooks.post.install_steps exists in no released GoReleaser. It arrives in v2.19 through goreleaser/goreleaser#6873 (open, closes goreleaser/goreleaser#6870). Until then CI here fails twice over: the pin check rejects the released 2.18.2, and goreleaser check rejects the field itself:

line 91: field install_steps not found in type config.HomebrewCaskHook

When v2.19 ships, re-running CI is enough — this PR already bumps .tool-versions to goreleaser 2.19.0.

Motivation

#510 works around Homebrew's deprecated postflight by writing the stanza through custom_block, at two costs: {{staged_path}} has to be escaped past GoReleaser's own template pass, and the stanza renders at the top of the cask, so every stanza after it trips Cask/StanzaOrder. #511 has to skip that cop to stay green.

GoReleaser v2.19 adds the first-class option, which removes all three.

Solution

Replace custom_block with hooks.post.install_steps, using GoReleaser's new .StagedPath field in place of the escape. Behaviour is unchanged — the step still clears quarantine on the whole staged dir, as #477 made it.

hooks:
  post:
    install_steps: |
      on_macos do
        run "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "{{ .StagedPath }}"]
      end

Also drops #511's --except-cops=Cask/StanzaOrder and its TODO(#512), and bumps the GoReleaser pin.

Validation

Built GoReleaser from #6873 at its head (38c7541) and ran it against this config:

The install itself was verified on #510 for the identical stanza: quarantine cleared across all 43 staged files, and lstk --version runs.

Stacking

Based on #511, so the diff reads as "replace the workaround". Retarget to main once #511 merges.

Docs

Nothing to document. No change to lstk's commands, flags, env vars or output, and no user-visible change to the cask's behaviour — this swaps the mechanism that generates an identical stanza.

Review

Human review advised: it touches the release pipeline, and merging it before v2.19 would break the release.

Todo

  • Wait for GoReleaser v2.19, then re-run CI
  • Confirm 2.19.0 is the version that actually ships #6873 before merging

Towards DEVX-1124

🤖 Generated with Claude Code

@joe4dev joe4dev added semver: patch docs: skip Pull request does not require documentation changes labels Sep 22, 2026
@joe4dev
joe4dev force-pushed the devx-1124-cask-install-steps branch from bc70c3a to ba7d03d Compare September 22, 2026 10:12
@joe4dev
joe4dev force-pushed the devx-1124-guard-generated-homebrew-cask branch 2 times, most recently from 75fb741 to dd3f443 Compare September 22, 2026 10:39
@joe4dev
joe4dev force-pushed the devx-1124-cask-install-steps branch from ba7d03d to 3170663 Compare September 22, 2026 10:41
@joe4dev
joe4dev force-pushed the devx-1124-guard-generated-homebrew-cask branch from dd3f443 to be579b7 Compare September 22, 2026 10:46
@joe4dev
joe4dev force-pushed the devx-1124-cask-install-steps branch from 3170663 to 476ffc4 Compare September 22, 2026 10:47
Co-Authored-By: Claude <noreply@anthropic.com>
@joe4dev
joe4dev force-pushed the devx-1124-guard-generated-homebrew-cask branch from be579b7 to 607b035 Compare September 22, 2026 12:56
Co-Authored-By: Claude <noreply@anthropic.com>
@joe4dev
joe4dev force-pushed the devx-1124-cask-install-steps branch from 476ffc4 to 7e5504e Compare September 22, 2026 12:57
@joe4dev
joe4dev force-pushed the devx-1124-guard-generated-homebrew-cask branch from 607b035 to 260bb75 Compare September 22, 2026 14:02
Base automatically changed from devx-1124-guard-generated-homebrew-cask to main September 23, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs: skip Pull request does not require documentation changes semver: patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant