diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 66f51faf..5c977d43 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1574,23 +1574,20 @@ jobs: && needs.version.result == 'success' && needs.publish.result == 'success' && needs.verify.result == 'success' && needs.version.outputs.prerelease == 'false' + && vars.WINGET_PUBLISH == 'true' runs-on: ubuntu-24.04 timeout-minutes: 15 concurrency: group: release-winget-${{ github.ref }} cancel-in-progress: false env: - WINGET_PUBLISH: ${{ vars.WINGET_PUBLISH }} WINGET_TOKEN: ${{ secrets.WINGET_TOKEN }} steps: - name: Is there anything to add a version to id: gate shell: bash run: | - if [ "$WINGET_PUBLISH" != "true" ]; then - echo "::notice::WINGET_PUBLISH is not true; winget-pkgs gets nothing until it is" - echo "go=no" >> "$GITHUB_OUTPUT" - elif [ -z "$WINGET_TOKEN" ]; then + if [ -z "$WINGET_TOKEN" ]; then echo "::error::WINGET_PUBLISH is on and there is no winget token, so this release \ would quietly never reach winget-pkgs. Set the secret or turn the switch off." exit 1 diff --git a/RELEASING.md b/RELEASING.md index c326dc70..596eb22a 100644 --- a/RELEASING.md +++ b/RELEASING.md @@ -97,10 +97,14 @@ refuses a package the community repository has never seen. Today 2. Submit the manifest by hand against that public URL: `wingetcreate new `. 3. Wait for a `winget-pkgs` moderator to merge it (days, not hours). -4. Only then set `vars.WINGET_PUBLISH=true` and `secrets.WINGET_TOKEN`. - -The `winget` job starts disabled by that variable, so it is harmless to ship -the workflow before the package exists: it logs a notice and does nothing. +4. Replace `winget-releaser`: it pulls `cargo-bins/cargo-binstall@main` + unpinned, which this repository's pinning policy refuses when the job is set + up, so the job fails before any step runs. `wingetcreate update` on a + Windows runner does the same without third-party actions. +5. Only then set `vars.WINGET_PUBLISH=true` and `secrets.WINGET_TOKEN`. + +The `winget` job is skipped whole while that variable is off, so it is +harmless to ship the workflow before the package exists. ### 2. Microsoft Store