Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions docs/releases/v0.1.0-alpha.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
**WorkHarbor v0.1.0-alpha.5** (pre-release): an alpha with a single install archive, built for macOS on Apple silicon.

- **Highlights:** one archive holds `bin/whr`, the Linux guest binaries and `install.sh`, replacing the separate script and guest archive (#489, #496); `whr setup` accepts a `whr` wherever it lies and drops `--dev` and `--managed` (breaking, #493, #501); `make install` and `install.sh` warn instead of refusing for a dirty tree, a non-main HEAD, a writable prefix or another owner (#493, #504, #506); setup can install Homebrew after a confirmation (#505, #508), warns early when the account cannot use sudo (#507, #511), and the doctor publishes and reads a system config at `/etc/whr/config.json` (#431, #509, #510, #512); review cards now go to Needs you and the Ready to push status is gone (#514, #516); the build pins the fixed Go 1.26.9 and 1.27.2 (#497, #500).
- **You can now:** install a release from one downloaded archive and `checksums.txt` with `curl`, `shasum`, `tar`, `install` and `sudo` alone, no `gh` needed.
- **Known limits:** unverified: this is the first release built as a single archive, so its upload and attestation, the Homebrew formula built from it and an install on a clean Apple-silicon Mac without `gh`, Homebrew or Command Line Tools have not run in a release yet.
- **Verify provenance:** `shasum -a 256 -c` on the archive (see Install); provenance is `whr_v0.1.0-alpha.5.intoto.jsonl`, checked with `gh attestation verify`.

## Install

macOS on Apple silicon; needs only `curl`, `shasum`, `tar`, `install` and `sudo`. One archive holds `bin/whr`, the Linux guest binaries in `guest/` (payload, never run on the Mac) and `install.sh`. The first block must print `whr_<version>_darwin_arm64.tar.gz: OK`; any other output is a failure, do not go on.

```bash
cd "$(mktemp -d)"
tag=v0.1.0-alpha.5; base=https://github.com/wstein/workharbor/releases/download/$tag
f=whr_${tag#v}_darwin_arm64.tar.gz
curl -fsSLO "$base/$f" -O "$base/checksums.txt" &&
grep " $f\$" checksums.txt | shasum -a 256 -c -
```

Then unpack and run the installer as the administrator; the prefix is `/opt/whr` (add another path as a second argument). Nothing is downloaded and no `gh` is needed:

```bash
tar -xzf "$f" &&
sudo ./install.sh "$tag"
```

Optional, once `gh` is installed (setup installs it) and signed in: verify who built the archive.

```bash
commit=$(gh api repos/wstein/workharbor/commits/refs/tags/$tag --jq .sha) &&
gh attestation verify "$f" --repo wstein/workharbor \
--signer-workflow wstein/workharbor/.github/workflows/release.yml \
--source-ref refs/tags/$tag --source-digest "$commit" \
--deny-self-hosted-runners
```

`install.sh` checks no attestation and does not tie the tag to the archive. The `workharbor` user must not be able to write the prefix. Full guide: [Install, upgrade and release](https://wstein.github.io/workharbor/docs/manual/install-upgrade-release/).
Loading