ci: drop release workflow, switch install URLs to raw/HEAD
Upstream Sync / sync (push) Successful in 13s

Gitea has no /releases/latest/download/<file> shortcut (GitHub-only),
so the URL we wired up last commit served 404. Switch all user-facing
install commands to /raw/HEAD/install.{sh,ps1} -- the HEAD ref resolves
to the default branch (secure-main) without naming it, gives a stable
"always latest" URL, and survives a future branch rename.

With install no longer routed through release assets, the release
workflow becomes dead weight: secure-main is the curated branch (every
merge is manually reviewed), so every commit there is already vetted.
A separate tagged-release step duplicates that gate without adding new
information. Drop .gitea/workflows/release.yml; tag manually if you
ever want an immutable audit checkpoint.

The orphan v1.1.7-secure.1 tag + release is left in place as a
historical snapshot; harmless and can be deleted from the Gitea UI
later if desired.
This commit is contained in:
omar
2026-05-21 03:47:26 +03:00
parent 32663a7b18
commit a5dd271588
9 changed files with 35 additions and 152 deletions
-117
View File
@@ -1,117 +0,0 @@
name: Release
# Triggered when a tag matching v* is pushed. Builds a Gitea release with
# install.sh + install.ps1 attached as assets, so README's
# `releases/latest/download/install.sh` URL resolves.
#
# Manual trigger also supported: workflow_dispatch with a tag input lets
# you re-publish assets onto an existing tag (idempotent — existing
# attachments are replaced).
on:
push:
tags:
- 'v*'
workflow_dispatch:
inputs:
tag:
description: 'Tag to publish (e.g. v1.0.0). Tag must already exist.'
required: true
jobs:
release:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Resolve tag
id: tag
run: |
if [ -n "${{ inputs.tag }}" ]; then
tag="${{ inputs.tag }}"
else
tag="${GITHUB_REF_NAME}"
fi
echo "name=${tag}" >> "$GITHUB_OUTPUT"
prev=$(git tag --sort=-version:refname | grep -v "^${tag}$" | head -n1 || true)
echo "prev=${prev}" >> "$GITHUB_OUTPUT"
- name: Build release notes
id: notes
run: |
tag="${{ steps.tag.outputs.name }}"
prev="${{ steps.tag.outputs.prev }}"
{
echo "## Changes"
echo
if [ -n "$prev" ]; then
git log --pretty='- %s (%h)' "${prev}..${tag}"
else
git log --pretty='- %s (%h)' "$tag"
fi
echo
echo "## Install"
echo
echo '**macOS / Linux:**'
echo '```bash'
echo "curl -fsSL ${{ github.server_url }}/${{ github.repository }}/releases/latest/download/install.sh | bash"
echo '```'
echo
echo '**Windows (PowerShell):**'
echo '```powershell'
echo "irm ${{ github.server_url }}/${{ github.repository }}/releases/latest/download/install.ps1 | iex"
echo '```'
} > release-notes.md
- name: Publish release with assets
env:
TOKEN: ${{ secrets.GITHUB_TOKEN }}
SERVER: ${{ github.server_url }}
REPO: ${{ github.repository }}
TAG: ${{ steps.tag.outputs.name }}
run: |
set -euo pipefail
api="${SERVER}/api/v1/repos/${REPO}"
notes=$(cat release-notes.md)
payload=$(jq -n --arg tag "$TAG" --arg notes "$notes" \
'{tag_name: $tag, name: ("ClawGod " + $tag), body: $notes, draft: false, prerelease: false}')
# Find or create the release for this tag.
existing=$(curl -fsSL -H "Authorization: token $TOKEN" \
"${api}/releases/tags/${TAG}" 2>/dev/null || echo "")
rel_id=$(echo "$existing" | jq -r '.id // empty')
if [ -z "$rel_id" ]; then
rel=$(curl -fsSL -X POST \
-H "Authorization: token $TOKEN" \
-H "Content-Type: application/json" \
-d "$payload" \
"${api}/releases")
rel_id=$(echo "$rel" | jq -r '.id')
echo "Created release $TAG (id=$rel_id)"
else
echo "Release $TAG already exists (id=$rel_id) — refreshing assets only"
fi
# Delete any pre-existing attachments with our names, then upload fresh.
assets=$(curl -fsSL -H "Authorization: token $TOKEN" \
"${api}/releases/${rel_id}/assets")
for name in install.sh install.ps1; do
old_id=$(echo "$assets" | jq -r --arg n "$name" '.[] | select(.name==$n) | .id' | head -n1)
if [ -n "$old_id" ]; then
curl -fsSL -X DELETE \
-H "Authorization: token $TOKEN" \
"${api}/releases/${rel_id}/assets/${old_id}"
echo "Deleted stale asset $name (id=$old_id)"
fi
curl -fsSL -X POST \
-H "Authorization: token $TOKEN" \
-H "Content-Type: multipart/form-data" \
-F "attachment=@${name}" \
"${api}/releases/${rel_id}/assets?name=${name}" >/dev/null
echo "Uploaded $name"
done
+6 -6
View File
@@ -27,12 +27,12 @@ Install these **before** running the ClawGod installer:
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows (PowerShell):**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
Green logo = patched. Orange logo = original.
@@ -125,12 +125,12 @@ If you'd rather invoke the installer directly (same effect, both paths fetch the
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
If you'd rather drop ClawGod and use Anthropic's original `claude update` (which manages its own paths and would overwrite our launcher), uninstall first:
@@ -143,13 +143,13 @@ bash ~/.clawgod/install.sh --uninstall
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash -s -- --uninstall
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash -s -- --uninstall
hash -r # refresh shell cache
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
```
Uninstall restores `claude.orig → claude` and removes the `clawgod` alias.
+6 -6
View File
@@ -27,12 +27,12 @@ ClawGod インストーラ実行**前**に揃えておくもの:
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows (PowerShell):**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
緑のロゴ = パッチ適用済み。オレンジのロゴ = オリジナル。
@@ -125,12 +125,12 @@ claude.orig # オリジナル未修正版(自動バックアップ)
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
ClawGod を外して Anthropic 本来の `claude update`(独自に管理されたパスへ書き込み、私たちの launcher を上書きします)を使いたい場合は、先にアンインストールしてください:
@@ -143,13 +143,13 @@ bash ~/.clawgod/install.sh --uninstall
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash -s -- --uninstall
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash -s -- --uninstall
hash -r # シェルキャッシュをリフレッシュ
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
```
アンインストールは `claude.orig` を `claude` に戻し、`clawgod` エイリアスを削除します。
+6 -6
View File
@@ -27,12 +27,12 @@
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows (PowerShell):**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
绿色 Logo = 已 Patch。橙色 Logo = 原版。
@@ -125,12 +125,12 @@ claude.orig # 原版未修改版本(自动备份)
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
如果你想脱离 ClawGod、使用 Anthropic 原本的 `claude update`(它会写到自己管的目录、并把我们的 launcher 替换掉),请先卸载:
@@ -143,13 +143,13 @@ bash ~/.clawgod/install.sh --uninstall
**macOS / Linux:**
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash -s -- --uninstall
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash -s -- --uninstall
hash -r # 刷新 shell 缓存
```
**Windows:**
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 -OutFile install.ps1; .\install.ps1 -Uninstall
```
卸载会把 `claude.orig` 还原成 `claude`,并移除 `clawgod` 别名。
@@ -26,13 +26,13 @@
### macOS / Linux
```bash
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash
```
### Windows (PowerShell)
```powershell
irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex
irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex
```
### 验证
@@ -161,7 +161,7 @@ CTF 场景的 Guard 策略应该偏宽松:
exit
# 卸载 ClawGod(如果需要)
curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash -s -- --uninstall
curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash -s -- --uninstall
# 移除 CTF rules
rm ~/.claude/rules/ctf-context.md
+4 -4
View File
@@ -73,15 +73,15 @@
</div>
<div class="install-panel active" id="panel-unix" role="tabpanel">
<div class="code-block">
<button class="copy-btn" data-copy="curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash">Copy</button>
<pre><span class="prompt">$ </span><span class="tok tok-cmd">curl</span> <span class="tok tok-flag">-fsSL</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">bash</span></pre>
<button class="copy-btn" data-copy="curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash">Copy</button>
<pre><span class="prompt">$ </span><span class="tok tok-cmd">curl</span> <span class="tok tok-flag">-fsSL</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">bash</span></pre>
</div>
<div class="install-note">Idempotent — safe to re-run. Bun, Node ≥ 18, ripgrep required.</div>
</div>
<div class="install-panel" id="panel-win" role="tabpanel">
<div class="code-block">
<button class="copy-btn" data-copy="irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex">Copy</button>
<pre><span class="prompt">&gt; </span><span class="tok tok-cmd">irm</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">iex</span></pre>
<button class="copy-btn" data-copy="irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex">Copy</button>
<pre><span class="prompt">&gt; </span><span class="tok tok-cmd">irm</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">iex</span></pre>
</div>
<div class="install-note">Idempotent — safe to re-run. Bun via <a href="https://bun.sh/install" target="_blank" rel="noopener">bun.sh</a> recommended.</div>
</div>
+3 -3
View File
@@ -1157,14 +1157,14 @@ const patches = [
// arg-quoting; payload must be UTF-16LE base64.
const psScript =
"$p=if($env:HTTPS_PROXY){$env:HTTPS_PROXY}elseif($env:HTTP_PROXY){$env:HTTP_PROXY}else{$null};" +
"$u='https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1';" +
"$u='https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1';" +
"if($p){iex(irm -Proxy $p $u)}else{iex(irm $u)}";
const psB64 = Buffer.from(psScript, 'utf16le').toString('base64');
return (
prefix +
`process.stderr.write("[clawgod] 'claude update' is handled by clawgod self-update.\\n[clawgod] To leave clawgod and use vanilla update: bash ~/.clawgod/install.sh --uninstall\\n[clawgod] Continuing now\\u2026\\n");` +
`const _w=process.platform==='win32';` +
`const _c=_w?['powershell','-NoProfile','-EncodedCommand','${psB64}']:['bash','-c','curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash'];` +
`const _c=_w?['powershell','-NoProfile','-EncodedCommand','${psB64}']:['bash','-c','curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash'];` +
`const _r=require('child_process').spawnSync(_c[0],_c.slice(1),{stdio:'inherit'});` +
`process.exit(_r.status||0);`
);
@@ -1396,7 +1396,7 @@ if ($normalizedBunBin.Equals($normalizedUserProfile, [StringComparison]::Ordinal
# absolute path since %USERPROFILE%-relative expansion doesn't apply.
$bunPathInCmd = $BunBin
}
$launcherContent = "@echo off`r`nif not exist `"$cliPathInCmd`" (`r`n echo clawgod: cli.cjs not found. Reinstall: irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 ^| iex`r`n exit /b 127`r`n)`r`nif not exist `"$bunPathInCmd`" (`r`n echo clawgod: bun not found at $bunPathInCmd. Install: https://bun.sh/install`r`n exit /b 127`r`n)`r`n`"$bunPathInCmd`" `"$cliPathInCmd`" %*"
$launcherContent = "@echo off`r`nif not exist `"$cliPathInCmd`" (`r`n echo clawgod: cli.cjs not found. Reinstall: irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 ^| iex`r`n exit /b 127`r`n)`r`nif not exist `"$bunPathInCmd`" (`r`n echo clawgod: bun not found at $bunPathInCmd. Install: https://bun.sh/install`r`n exit /b 127`r`n)`r`n`"$bunPathInCmd`" `"$cliPathInCmd`" %*"
# Find and back up original claude
$claudeCmd = Join-Path $BinDir "claude.cmd"
+3 -3
View File
@@ -1038,14 +1038,14 @@ const patches = [
// arg-quoting; payload must be UTF-16LE base64.
const psScript =
"$p=if($env:HTTPS_PROXY){$env:HTTPS_PROXY}elseif($env:HTTP_PROXY){$env:HTTP_PROXY}else{$null};" +
"$u='https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1';" +
"$u='https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1';" +
"if($p){iex(irm -Proxy $p $u)}else{iex(irm $u)}";
const psB64 = Buffer.from(psScript, 'utf16le').toString('base64');
return (
prefix +
`process.stderr.write("[clawgod] 'claude update' is handled by clawgod self-update.\\n[clawgod] To leave clawgod and use vanilla update: bash ~/.clawgod/install.sh --uninstall\\n[clawgod] Continuing now\\u2026\\n");` +
`const _w=process.platform==='win32';` +
`const _c=_w?['powershell','-NoProfile','-EncodedCommand','${psB64}']:['bash','-c','curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash'];` +
`const _c=_w?['powershell','-NoProfile','-EncodedCommand','${psB64}']:['bash','-c','curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash'];` +
`const _r=require('child_process').spawnSync(_c[0],_c.slice(1),{stdio:'inherit'});` +
`process.exit(_r.status||0);`
);
@@ -1341,7 +1341,7 @@ CLAWGOD_CLI=\"$CLAWGOD_DIR/cli.cjs\"
BUN_BIN=\"$BUN_BIN\"
if [ ! -f \"\$CLAWGOD_CLI\" ]; then
echo \"clawgod: installation at $CLAWGOD_DIR is missing (cli.cjs not found)\" >&2
echo \"clawgod: reinstall via curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash\" >&2
echo \"clawgod: reinstall via curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash\" >&2
echo \"clawgod: or remove this launcher: rm \\\"\$0\\\"\" >&2
exit 127
fi
+4 -4
View File
@@ -73,15 +73,15 @@
</div>
<div class="install-panel active" id="panel-unix" role="tabpanel">
<div class="code-block">
<button class="copy-btn" data-copy="curl -fsSL https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh | bash">Copy</button>
<pre><span class="prompt">$ </span><span class="tok tok-cmd">curl</span> <span class="tok tok-flag">-fsSL</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/releases/latest/download/install.sh</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">bash</span></pre>
<button class="copy-btn" data-copy="curl -fsSL https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh | bash">Copy</button>
<pre><span class="prompt">$ </span><span class="tok tok-cmd">curl</span> <span class="tok tok-flag">-fsSL</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/raw/HEAD/install.sh</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">bash</span></pre>
</div>
<div class="install-note">Idempotent — safe to re-run. Bun, Node ≥ 18, ripgrep required.</div>
</div>
<div class="install-panel" id="panel-win" role="tabpanel">
<div class="code-block">
<button class="copy-btn" data-copy="irm https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1 | iex">Copy</button>
<pre><span class="prompt">&gt; </span><span class="tok tok-cmd">irm</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/releases/latest/download/install.ps1</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">iex</span></pre>
<button class="copy-btn" data-copy="irm https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1 | iex">Copy</button>
<pre><span class="prompt">&gt; </span><span class="tok tok-cmd">irm</span> <span class="tok tok-url">https://git.qomar.pw/omar/clawgod/raw/HEAD/install.ps1</span> <span class="tok tok-op">|</span> <span class="tok tok-cmd">iex</span></pre>
</div>
<div class="install-note">Idempotent — safe to re-run. Bun via <a href="https://bun.sh/install" target="_blank" rel="noopener">bun.sh</a> recommended.</div>
</div>