Context
The release flow now correctly creates a draft, smoke-tests it, and publishes only after success. The remaining privilege boundary is broad: the build/sign/notarize job has contents: write, repository-level Apple secrets, and a checkout that persists the GitHub credential.
Proposed change
- Create a GitHub
release environment restricted to v* tags.
- Move
MACOS_CERTIFICATE, MACOS_CERTIFICATE_PWD, APPLE_ID, APPLE_TEAM_ID, and APPLE_APP_PASSWORD from repository secrets to that environment.
- Give the build/sign/notarize job only
contents: read and set persist-credentials: false on checkout.
- Pass verified artifacts to a separate job that alone has
contents: write and creates or updates the draft release.
- Keep the smoke-test and publish jobs separate; do not expose Apple credentials to either.
- Add explicit job timeouts and pin the release runner image deliberately rather than relying indefinitely on
macos-latest.
Acceptance criteria
Maintainer setting required
Create and configure the release environment and migrate the five existing repository secrets.
Context
The release flow now correctly creates a draft, smoke-tests it, and publishes only after success. The remaining privilege boundary is broad: the build/sign/notarize job has
contents: write, repository-level Apple secrets, and a checkout that persists the GitHub credential.Proposed change
releaseenvironment restricted tov*tags.MACOS_CERTIFICATE,MACOS_CERTIFICATE_PWD,APPLE_ID,APPLE_TEAM_ID, andAPPLE_APP_PASSWORDfrom repository secrets to that environment.contents: readand setpersist-credentials: falseon checkout.contents: writeand creates or updates the draft release.macos-latest.Acceptance criteria
contents: write.releaseenvironment.Maintainer setting required
Create and configure the
releaseenvironment and migrate the five existing repository secrets.