diff --git a/docs/releases/v0.1.0-alpha.5.md b/docs/releases/v0.1.0-alpha.5.md new file mode 100644 index 00000000..21886b79 --- /dev/null +++ b/docs/releases/v0.1.0-alpha.5.md @@ -0,0 +1,37 @@ +**WorkHarbor v0.1.0-alpha.5** (pre-release): an alpha with a single install archive, built for macOS on Apple silicon. + +- **Highlights:** one archive holds `bin/whr`, the Linux guest binaries and `install.sh`, replacing the separate script and guest archive (#489, #496); `whr setup` accepts a `whr` wherever it lies and drops `--dev` and `--managed` (breaking, #493, #501); `make install` and `install.sh` warn instead of refusing for a dirty tree, a non-main HEAD, a writable prefix or another owner (#493, #504, #506); setup can install Homebrew after a confirmation (#505, #508), warns early when the account cannot use sudo (#507, #511), and the doctor publishes and reads a system config at `/etc/whr/config.json` (#431, #509, #510, #512); review cards now go to Needs you and the Ready to push status is gone (#514, #516); the build pins the fixed Go 1.26.9 and 1.27.2 (#497, #500). +- **You can now:** install a release from one downloaded archive and `checksums.txt` with `curl`, `shasum`, `tar`, `install` and `sudo` alone, no `gh` needed. +- **Known limits:** unverified: this is the first release built as a single archive, so its upload and attestation, the Homebrew formula built from it and an install on a clean Apple-silicon Mac without `gh`, Homebrew or Command Line Tools have not run in a release yet. +- **Verify provenance:** `shasum -a 256 -c` on the archive (see Install); provenance is `whr_v0.1.0-alpha.5.intoto.jsonl`, checked with `gh attestation verify`. + +## Install + +macOS on Apple silicon; needs only `curl`, `shasum`, `tar`, `install` and `sudo`. One archive holds `bin/whr`, the Linux guest binaries in `guest/` (payload, never run on the Mac) and `install.sh`. The first block must print `whr__darwin_arm64.tar.gz: OK`; any other output is a failure, do not go on. + +```bash +cd "$(mktemp -d)" +tag=v0.1.0-alpha.5; base=https://github.com/wstein/workharbor/releases/download/$tag +f=whr_${tag#v}_darwin_arm64.tar.gz +curl -fsSLO "$base/$f" -O "$base/checksums.txt" && +grep " $f\$" checksums.txt | shasum -a 256 -c - +``` + +Then unpack and run the installer as the administrator; the prefix is `/opt/whr` (add another path as a second argument). Nothing is downloaded and no `gh` is needed: + +```bash +tar -xzf "$f" && +sudo ./install.sh "$tag" +``` + +Optional, once `gh` is installed (setup installs it) and signed in: verify who built the archive. + +```bash +commit=$(gh api repos/wstein/workharbor/commits/refs/tags/$tag --jq .sha) && +gh attestation verify "$f" --repo wstein/workharbor \ + --signer-workflow wstein/workharbor/.github/workflows/release.yml \ + --source-ref refs/tags/$tag --source-digest "$commit" \ + --deny-self-hosted-runners +``` + +`install.sh` checks no attestation and does not tie the tag to the archive. The `workharbor` user must not be able to write the prefix. Full guide: [Install, upgrade and release](https://wstein.github.io/workharbor/docs/manual/install-upgrade-release/).