git-crypt-windows-builds
> This is NOT git-crypt. This repo contains no git-crypt source code of its own. It is a small
> automation helper, unaffiliated with and not endorsed by AGWA (git-crypt's author), that watches
> AGWA/git-crypt — the real, official project — for new releases and:
>
> - if AGWA already published an official Windows .exe for that release, points winget at AGWA's own file
> directly (nothing built or hosted here);
> - if AGWA did not publish one for that release (as happened with
> 0.8.0), compiles one itself from AGWA's unmodified
> published source and hosts that build here instead, clearly labeled as unofficial.
>
> Any .exe released from this repo is an unofficial, unsigned, community-built binary. It is not
> reviewed, tested, or distributed by AGWA. For the official releases (when available), always prefer
> https://github.com/AGWA/git-crypt/releases.
Keeps a Windows build of git-crypt available and submitted to
winget-pkgs, even when upstream's own Windows CI fails to
publish one for a release.
What it does
.github/workflows/sync-release.yml runs daily (and on manual dispatch):
- Checks the latest
AGWA/git-crypt release.
- Skips it if this repo already has a release with that tag.
- If AGWA's release already includes an official
*-x86_64.exe asset, it records that and submits/updates
the AGWA.git-crypt winget manifest pointing straight at AGWA's own asset URL.
- If no official Windows asset exists, it builds one itself from the unmodified upstream source (same
MSYS2/MinGW recipe as upstream's own
release-windows.yml), publishes it as a release in this repo, and
submits/updates the ja-ortiz-uniandes.git-crypt-unofficial winget manifest instead — clearly labeled
as an unofficial, unsigned community build.
This keeps the two identities separate: AGWA.git-crypt in winget only ever points to binaries AGWA
actually published themselves. The unofficial identifier is the fallback, used only for versions upstream
never shipped a Windows binary for.
One-time setup
1. WINGET_PAT secret
wingetcreate needs a classic GitHub PAT with the public_repo scope (nothing broader) to fork
microsoft/winget-pkgs and open PRs on your behalf. Create one at
https://github.com/settings/tokens/new, then add it locally (don't paste the token into a chat/tool that logs it):
gh secret set WINGET_PAT --repo ja-ortiz-uniandes/git-crypt-windows-builds
Without this secret, the workflow still mirrors/builds releases but skips the winget submission step
(logs a warning instead).
2. First submission per package identifier
wingetcreate update only works once a manifest already exists for that identifier — it can't create one
from nothing. The very first version of each identifier needs a one-time manual bootstrap:
wingetcreate.exe new --submit --token
Run this once for AGWA.git-crypt (using an official AGWA asset URL) and once for
ja-ortiz-uniandes.git-crypt-unofficial (using one of this repo's release asset URLs). After that, the
scheduled workflow's update calls handle every future version automatically.
Manual run
Trigger Actions -> sync-git-crypt-release -> Run workflow any time instead of waiting for the daily
schedule.