Tasklight uses two supported installation channels beginning with v0.2.0.
The npm package is the primary prebuilt distribution:
npm install -g @tasklight/cliIt contains Go binaries for macOS/Linux on arm64/amd64 and the ad hoc signed native macOS notification helper. npm publication uses trusted OIDC publishing and provenance.
The supported Homebrew command is:
brew install revazi/tap/tasklightThe formula is maintained in revazi/homebrew-tap. It builds the tagged Tasklight source with Homebrew's Go toolchain. On macOS it also builds the native helper locally with the installed Xcode toolchain, applies the same hardened-runtime/ad hoc checks, and installs a wrapper that selects that helper. Linux builds install the CLI and use the documented notify-send dependency.
Building the helper locally avoids presenting an unnotarized, directly downloaded .app as an Apple-identified application. The future standalone signing/notarization requirements remain documented in MACOS_HELPER.md.
For a version tag, the release workflow:
- Verifies package, tag, and changelog metadata.
- Runs repository, package, native-helper, and installation checks.
- Creates a source archive from the checked-out immutable tag and records its SHA-256.
- Generates and validates a versioned
tasklight.rbformula that uses that release asset. - Publishes npm through the protected environment.
- Creates the matching GitHub release with the source archive,
tasklight.rb, andsource-checksum.txtattached.
After the GitHub release exists, copy the generated formula into Formula/tasklight.rb in revazi/homebrew-tap, review its source URL and checksum, and test:
brew update
brew upgrade revazi/tap/tasklight
# or, for a clean validation
brew uninstall tasklight
brew install revazi/tap/tasklight
tasklight --version
tasklight doctor
brew test revazi/tap/tasklightThe Git tag, GitHub release, npm latest, formula version, and formula source URL must all agree before announcing a release. After updating the tap, run:
./scripts/verify-release-state.sh X.Y.ZTasklight does not currently publish a curl | sh installer. Avoiding an install script keeps executable placement, upgrades, and uninstallation under npm or Homebrew package-manager control.
GitHub automatically provides source archives for each release. Prebuilt standalone macOS app archives are intentionally deferred until Developer ID signing and notarization are available. See MACOS_HELPER.md.