Skip to content

Commit 036f1f8

Browse files
authored
ci: build the flake and guard the version literal (#39)
Two gaps the nix packaging left open: - Nothing built the flake, so a go.sum move that stales vendorHash stayed invisible until someone installed the CLI with nix. The new `nix` job builds chrome-cdp and runs the binary, so the PR that moves go.sum goes red. - flake.nix carries the version as a literal, because a flake building `src = self` has no git tag to read. The release workflow now fails when the tag and that literal disagree, rather than shipping a binary that reports the wrong version.
1 parent 54d7701 commit 036f1f8

2 files changed

Lines changed: 29 additions & 0 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,3 +77,19 @@ jobs:
7777

7878
- name: Test the npm installer shim
7979
run: cd npm && node --test
80+
81+
# The flake is how this CLI reaches nix users (sanketsudake/dotfiles installs
82+
# it that way), and its vendorHash goes stale whenever go.sum moves. Building
83+
# it here makes the PR that moves go.sum go red, instead of the break landing
84+
# on a machine downstream.
85+
nix:
86+
runs-on: ubuntu-latest
87+
steps:
88+
- uses: actions/checkout@v4
89+
- uses: cachix/install-nix-action@v31
90+
with:
91+
extra_nix_config: "experimental-features = nix-command flakes"
92+
- name: Build the flake package
93+
run: nix build .#chrome-cdp --print-build-logs
94+
- name: Smoke-test the built binary
95+
run: ./result/bin/chrome-cdp --version

‎.github/workflows/release.yml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,19 @@ jobs:
2020
go-version-file: go.mod
2121
cache: true
2222

23+
24+
# A flake building `src = self` has no git tag to read, so flake.nix
25+
# carries the version as a literal. Fail the release rather than ship a
26+
# binary that reports the wrong version to nix users.
27+
- name: flake.nix version matches the tag
28+
run: |
29+
tag="${GITHUB_REF_NAME#v}"
30+
flake=$(sed -n 's/^ *version = "\(.*\)";$/\1/p' flake.nix)
31+
if [ "$tag" != "$flake" ]; then
32+
echo "::error::tag $tag does not match flake.nix version $flake"
33+
exit 1
34+
fi
35+
2336
- uses: goreleaser/goreleaser-action@v6
2437
with:
2538
version: "~> v2"

0 commit comments

Comments
 (0)