These scripts help automate the release process for strongbox.
They run on the host and need only bash, coreutils and docker. Every step runs in a short-lived container
built from pinned images (see pins.env). Repositories are cloned fresh for each release into
work/, and credentials are given only to the steps that write to a remote.
Packaging files are rendered from templates/ into dist/, with every version, URL and checksum
written out in full, in the way makepkg renders a PKGBUILD. publish commits dist/ and tags this
repository <version>, so each strongbox release maps to a tag here showing what was generated and pushed.
The Flathub and AUR repositories hold only copies of files in dist/.
See release.md for the full checklist.
./prep.sh <version> [branch]
Prepares a release branch of strongbox for review.
- checks the GitHub token.
- clones strongbox at
branch(defaultdevelop) and checks the version is greater than the last release. - creates a release branch, updates
project.clj,CHANGELOG.md,README.md,SECURITY.md(major releases) and regeneratespom.xml. - shows the commit and asks for the version to be typed.
- pushes the branch and opens a PR against
master.
./release.sh build <version>
Assumes the prep PR has been merged into master. Changes nothing remote and uses no credentials.
- clones strongbox, the Flathub repository and the AUR package.
- checks the Flathub and AUR repositories still hold what was last pushed to them (see "drift" below).
- checks
masterdeclares the version, the changelog has it, and any existing tag points atmaster. - builds the uberjar, and the AppImage with
appimage/build-appimage.shand a JRE from the pinned Temurin 17 JDK. - checks no shared object in the AppImage needs a glibc newer than
GLIBC_CEILING, and that its JRE starts on that glibc. - renders
templates/with the version and the artefacts' checksums. - runs Flathub's linter on the manifest and metainfo, and builds the AUR package offline from the local AppImage.
- copies the rendered files into the Flathub and AUR clones as local commits.
- writes
dist/build.json, a record of every input and output, then replacesdist/with the rendered files.
A build that fails leaves dist/ unchanged. Review git diff dist/ before publishing.
./release.sh adopt {flathub|aur}
build stops if a downstream repository differs from what was last pushed to it, for example when a
Flathub contributor changes the runtime. Move the change into templates/, then run adopt to copy the
downstream files into dist/<target>, review git diff dist/<target> and commit. adopt changes nothing remote.
./release.sh publish <version>
Publishes exactly what build recorded. Runs on master, with no uncommitted changes outside dist/.
Checks the record still matches the workspace and dist/, checks the GitHub token, shows what will be
done and asks for the version to be typed. Then, in order:
- commits
dist/asrelease <version>, tags this repository<version>, and pushes both. - tags the strongbox release.
- creates the GitHub release.
- uploads the artefacts.
- opens a PR on Flathub. Its manifest fetches
dist/flatpak/at this repository's tag. - updates the AUR.
Steps already done are skipped, so it can be rerun after a failure. It stops without changing anything when remote state differs from the build.
python3 -m unittest discover -s tests
./check-pins.sh
tests/integration-build.sh <version>
tests/integration-prep.sh
tests/integration-publish.sh
ogri-la/strongbox-flatpak, ogri-la/strongbox-pkgbuild and ogri-la/strongbox-appimage are no longer
used. Their content is now in templates/, dist/ and appimage/.