Skip to content

fix(release): use notarization broker - #110

Merged
trsdn merged 6 commits into
mainfrom
fix/use-notarization-broker
Sep 22, 2026
Merged

trsdn merged 6 commits into
mainfrom
fix/use-notarization-broker

Conversation

@trsdn

@trsdn trsdn commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Moves the release trust boundary out of OpenWritr and into the public trsdn/macos-notarization-broker profile openwritr.

  • removes the direct tag-triggered signing/notarization workflow, Apple secret setup, local notary configuration, and direct notarization scripts
  • authenticates the broker workflow run and immutable Actions artifact digest before trusting provenance or release bytes
  • validates the source repository/tag/SHA, profile and preflight identity, Developer ID Team and bundle ID, exact broker artifacts, byte-identical AppUpdater alias, and ZIP-only attestation manifest
  • creates a single-use draft with exactly the established five public assets; existing drafts/releases are never updated or clobbered
  • dispatches the read-only transcription smoke workflow against the draft, rechecks the immutable tag and every asset byte, then publishes and verifies all five public bytes again
  • keeps local signed app/DMG creation explicitly diagnostic and removes every OpenWritr Apple credential surface

Closes #58.

Depends on trsdn/macos-notarization-broker#69, which must merge first. That PR aligns the broker build/profile with OpenWritr, creates the AppUpdater alias, and ensures only the ZIP is attested while both DMG digests remain unattested for #31 compatibility.

Generated with GitHub Copilot.

Validation

  • swift build -c release -Xswiftc -warnings-as-errors
  • swiftlint lint --strict
  • swift test (38 tests)
  • bash -n scripts/*.sh
  • PYTHONPATH=scripts python3 -m unittest scripts/test_verify_broker_artifacts.py -v (4 tests)
  • Python compile and workflow YAML parse
  • git diff --check
  • Coordinated broker PR full suite (242 tests plus static validation); all GitHub checks pass

Impact

  • Operational risk: release publication becomes an explicit maintainer-only broker request followed by a single-use draft → smoke → publish handoff. A failed unpublished attempt requires deleting the draft before retrying.
  • Security/privacy: OpenWritr no longer stores or reads Apple credentials. The handoff uses the maintainer's existing gh identity, verifies numeric actor/repository/workflow identities and artifact digests, and no source workflow can access broker secrets.
  • Compatibility: public asset names remain exactly unchanged, including OpenWritr-{version}.dmg. Neither OpenWritr DMG may be attested; the ZIP may be.

After this PR and broker PR #69 merge, these obsolete OpenWritr secrets can be deleted: MACOS_CERTIFICATE, MACOS_CERTIFICATE_PWD, APPLE_ID, APPLE_TEAM_ID, and APPLE_APP_PASSWORD.

Remove Apple credential handling and direct signing from OpenWritr. Authenticate broker artifacts, create a single-use five-asset draft, smoke-test it, and publish only after immutable tag and byte-for-byte checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI lite review requested due to automatic review settings September 22, 2026 19:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical smoke-test access and release-handoff validation issues block safe publication.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity · 2 Medium severity

Open (4)
What changed in this PR

Moves macOS signing and notarization to the external broker, adding verified artifact publication while removing OpenWritr Apple credential surfaces.

Changes:

  • Removes direct release, signing, notarization, and credential setup tooling.
  • Adds broker provenance, digest, asset, and attestation validation.
  • Updates smoke testing, CI, documentation, and release guidance.
File Reviewed changes and findings
Sources/​OpenWritr/​UpdateManager.swift Documents broker-based release provenance.
scripts/​verify_broker_artifacts.py Validates broker provenance and release artifacts.
scripts/​test_verify_broker_artifacts.py Tests artifact validation.
scripts/​setup_notarization.sh Removes obsolete credential setup.
scripts/​release_macos.sh Removes direct release tooling.
scripts/​publish_broker_release.sh Implements draft, smoke-test, and publish handoff. Critical, 1 vote (line 221): smoke-run correlation can select another same-tag run. Moderate, 2 votes (line 169): + in the tag is not URL-encoded. Moderate, 2 votes (line 184): changelog matching does not escape +. Moderate, 1 vote (line 13): accepted build-metadata tags are unsupported by the handoff.
scripts/​notarize_dmg.sh Removes obsolete DMG notarization.
scripts/​notarize_app.sh Removes obsolete app notarization.
scripts/​make_dmg.sh Removes obsolete environment loading.
scripts/​build-app.sh Retains local diagnostic build behavior.
RELEASE_CHECKLIST.md Documents the broker release procedure.
README.md Updates distribution and verification guidance.
docs/​self-assessment.md Updates conformance documentation.
docs/​release-smoke-tests.md Documents draft smoke testing.
CHANGELOG.md Updates release-note ownership.
AGENTS.md Documents the new trust boundary and credential guidance.
.release.env.example Removes obsolete configuration template.
.gitignore Removes the .release.env ignore. Moderate, 1 vote: retaining this ignore is needed to prevent accidental credential-file commits.
.github/​workflows/​smoke-test.yml Runs release smoke tests. Critical, 2 votes: its read-only token cannot access draft assets, preventing publication.
.github/​workflows/​release.yml Removes the direct signing workflow.
.github/​workflows/​ci.yml Adds release-tooling validation.
.github/​github-app.yml Updates agent release restrictions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/smoke-test.yml
Comment thread scripts/publish_broker_release.sh Outdated
Comment thread scripts/publish_broker_release.sh Outdated
Comment thread scripts/publish_broker_release.sh Outdated
Bind draft smoke runs to trusted main, authenticated artifact digests, and a
unique nonce. Extract changelog notes with literal version matching so SemVer
build metadata is handled safely.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 19:37
Comment thread scripts/publish_broker_release.sh Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Two unresolved critical findings remain regarding .release.env protection and canonical checksum validation.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (4)

Comment thread scripts/verify_broker_artifacts.py

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No high-confidence, actionable HIG defects were found that are introduced or exposed by this pull request. Why: The only change in this PR is a doc-comment update in Sources/OpenWritr/UpdateManager.swift explaining why GitHubAttestationPolicy is not used for update attestation. No SwiftUI/AppKit view, state-machine, accessibility, or string-literal code is touched, so none of the rendered UI surfaces below could have been affected by this change. Rendered surfaces reviewed (light/dark, plus accessibility-text variants where provided): Settings (settings-light.png, settings-dark.png, settings-light-accessibility-text.png); About (about-light.png, about-dark.png, about-dark-accessibility-text.png); Recording/transcription overlay states - listening, transcribing, enhancing, done, error (light/dark each). No layout clipping, contrast, focus, or state-transition anomalies were observed in these renders that trace back to this diff.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 19:50

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved moderate verification and release-note issues remain, along with related documentation corrections.

Review effort: Lite
Findings: 1 High severity

Open (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Update no-attestation rationale for the current broker workflow

AGENTS.md:80

The preceding bullet still says releases are built by a tag-push workflow, but this PR removes that workflow and moves signing to the broker's workflow_dispatch from main. That makes the #31 rationale inaccurate and can send maintainers toward the retired release path; update the no-attestation explanation to describe the current broker/source-ref boundary.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 19:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved artifact-checksum and release-download verification findings affect the release trust boundary.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Remove inaccurate Swift unit-test coverage claim

docs/​release-smoke-tests.md:65

AGENTS.md:123 explicitly says the Swift unit tests do not cover audio, hotkey, or paste behavior, so this sentence claims coverage that does not exist. Please remove the unit-test claim and leave the pull-request manual check as the coverage mechanism; otherwise maintainers may skip the required hands-on validation.

Comment thread scripts/verify_broker_artifacts.py Outdated
@trsdn
trsdn enabled auto-merge (squash) September 22, 2026 20:06

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rendered UI review PR 110. Diff scope: only change is a doc-comment update in Sources/OpenWritr/UpdateManager.swift (lines ~52-61) explaining why GitHubAttestationPolicy is not used for update verification; no SwiftUI/AppKit view, string, color, or asset changes. Surfaces reviewed: Settings (light, dark, light accessibility-text), About (light, dark, dark accessibility-text), and overlay states listening/transcribing/enhancing/done/error in light and dark. Findings: no high-confidence actionable HIG defects introduced or exposed by this PR; the change is confined to an internal comment with no rendering effect, so none of the reviewed screenshots are attributable to this diff, and no pre-existing issue in these surfaces is newly triggered or exposed. No UI action needed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 20:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Address the two unresolved critical findings: preserve .release.env in .gitignore and remove unsafe eval use in the publication test.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread scripts/test_publish_broker_release.sh

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

macOS UI review — PR #110

Scope check: The PR diff (Sources/OpenWritr/UpdateManager.swift) only rewrites a doc comment explaining why GitHubAttestationPolicy is not used for update verification. It contains no changes to any SwiftUI view, view model, or asset, so no rendered UI surface can be introduced or exposed by this change.

Surfaces reviewed for completeness against the fixed HIG criteria (native control semantics, keyboard/focus, accessibility names/state, semantic colors/text styles, Reduce Motion, loading/disabled/error/success states, and microphone/transcript/clipboard/provider-handoff/credential privacy):

  • Settings: light, dark, light plus accessibility (larger) text
  • About: light, dark, dark plus accessibility (larger) text
  • Recording overlay: listening, transcribing, enhancing, done, error (light and dark each)

Result: No high-confidence, actionable HIG defects introduced or exposed by this pull request were found. The change is a code-comment-only clarification with no rendered UI impact, and the screenshots reflect pre-existing production UI state rather than anything altered by this diff.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 21:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

A moderate regression-test gap remains, and the broker-based release handoff is high-risk.

Review effort: Lite
Findings: None

Resolved since last review (1)

@trsdn
trsdn merged commit bf94265 into main Sep 22, 2026
13 checks passed
@trsdn
trsdn deleted the fix/use-notarization-broker branch September 22, 2026 21:29

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Test body content

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci(release): isolate signing secrets from publishing permissions

3 participants