You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Moves the release trust boundary out of OpenWritr and into the public trsdn/macos-notarization-broker profile openwritr.
removes the direct tag-triggered signing/notarization workflow, Apple secret setup, local notary configuration, and direct notarization scripts
authenticates the broker workflow run and immutable Actions artifact digest before trusting provenance or release bytes
validates the source repository/tag/SHA, profile and preflight identity, Developer ID Team and bundle ID, exact broker artifacts, byte-identical AppUpdater alias, and ZIP-only attestation manifest
creates a single-use draft with exactly the established five public assets; existing drafts/releases are never updated or clobbered
dispatches the read-only transcription smoke workflow against the draft, rechecks the immutable tag and every asset byte, then publishes and verifies all five public bytes again
keeps local signed app/DMG creation explicitly diagnostic and removes every OpenWritr Apple credential surface
Depends on trsdn/macos-notarization-broker#69, which must merge first. That PR aligns the broker build/profile with OpenWritr, creates the AppUpdater alias, and ensures only the ZIP is attested while both DMG digests remain unattested for #31 compatibility.
Generated with GitHub Copilot.
Validation
swift build -c release -Xswiftc -warnings-as-errors
Coordinated broker PR full suite (242 tests plus static validation); all GitHub checks pass
Impact
Operational risk: release publication becomes an explicit maintainer-only broker request followed by a single-use draft → smoke → publish handoff. A failed unpublished attempt requires deleting the draft before retrying.
Security/privacy: OpenWritr no longer stores or reads Apple credentials. The handoff uses the maintainer's existing gh identity, verifies numeric actor/repository/workflow identities and artifact digests, and no source workflow can access broker secrets.
Compatibility: public asset names remain exactly unchanged, including OpenWritr-{version}.dmg. Neither OpenWritr DMG may be attested; the ZIP may be.
After this PR and broker PR #69 merge, these obsolete OpenWritr secrets can be deleted: MACOS_CERTIFICATE, MACOS_CERTIFICATE_PWD, APPLE_ID, APPLE_TEAM_ID, and APPLE_APP_PASSWORD.
Remove Apple credential handling and direct signing from OpenWritr. Authenticate broker artifacts, create a single-use five-asset draft, smoke-test it, and publish only after immutable tag and byte-for-byte checks.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Moves macOS signing and notarization to the external broker, adding verified artifact publication while removing OpenWritr Apple credential surfaces.
Changes:
Removes direct release, signing, notarization, and credential setup tooling.
Adds broker provenance, digest, asset, and attestation validation.
Updates smoke testing, CI, documentation, and release guidance.
File
Reviewed changes and findings
Sources/OpenWritr/UpdateManager.swift
Documents broker-based release provenance.
scripts/verify_broker_artifacts.py
Validates broker provenance and release artifacts.
scripts/test_verify_broker_artifacts.py
Tests artifact validation.
scripts/setup_notarization.sh
Removes obsolete credential setup.
scripts/release_macos.sh
Removes direct release tooling.
scripts/publish_broker_release.sh
Implements draft, smoke-test, and publish handoff. Critical, 1 vote (line 221): smoke-run correlation can select another same-tag run. Moderate, 2 votes (line 169):+ in the tag is not URL-encoded. Moderate, 2 votes (line 184): changelog matching does not escape +. Moderate, 1 vote (line 13): accepted build-metadata tags are unsupported by the handoff.
scripts/notarize_dmg.sh
Removes obsolete DMG notarization.
scripts/notarize_app.sh
Removes obsolete app notarization.
scripts/make_dmg.sh
Removes obsolete environment loading.
scripts/build-app.sh
Retains local diagnostic build behavior.
RELEASE_CHECKLIST.md
Documents the broker release procedure.
README.md
Updates distribution and verification guidance.
docs/self-assessment.md
Updates conformance documentation.
docs/release-smoke-tests.md
Documents draft smoke testing.
CHANGELOG.md
Updates release-note ownership.
AGENTS.md
Documents the new trust boundary and credential guidance.
.release.env.example
Removes obsolete configuration template.
.gitignore
Removes the .release.env ignore. Moderate, 1 vote: retaining this ignore is needed to prevent accidental credential-file commits.
Bind draft smoke runs to trusted main, authenticated artifact digests, and a
unique nonce. Extract changelog notes with literal version matching so SemVer
build metadata is handled safely.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
The reason will be displayed to describe this comment to others. Learn more.
No high-confidence, actionable HIG defects were found that are introduced or exposed by this pull request. Why: The only change in this PR is a doc-comment update in Sources/OpenWritr/UpdateManager.swift explaining why GitHubAttestationPolicy is not used for update attestation. No SwiftUI/AppKit view, state-machine, accessibility, or string-literal code is touched, so none of the rendered UI surfaces below could have been affected by this change. Rendered surfaces reviewed (light/dark, plus accessibility-text variants where provided): Settings (settings-light.png, settings-dark.png, settings-light-accessibility-text.png); About (about-light.png, about-dark.png, about-dark-accessibility-text.png); Recording/transcription overlay states - listening, transcribing, enhancing, done, error (light/dark each). No layout clipping, contrast, focus, or state-transition anomalies were observed in these renders that trace back to this diff.
Update no-attestation rationale for the current broker workflow
AGENTS.md:80
The preceding bullet still says releases are built by a tag-push workflow, but this PR removes that workflow and moves signing to the broker's workflow_dispatch from main. That makes the #31 rationale inaccurate and can send maintainers toward the retired release path; update the no-attestation explanation to describe the current broker/source-ref boundary.
AGENTS.md:123 explicitly says the Swift unit tests do not cover audio, hotkey, or paste behavior, so this sentence claims coverage that does not exist. Please remove the unit-test claim and leave the pull-request manual check as the coverage mechanism; otherwise maintainers may skip the required hands-on validation.
The reason will be displayed to describe this comment to others. Learn more.
Rendered UI review PR 110. Diff scope: only change is a doc-comment update in Sources/OpenWritr/UpdateManager.swift (lines ~52-61) explaining why GitHubAttestationPolicy is not used for update verification; no SwiftUI/AppKit view, string, color, or asset changes. Surfaces reviewed: Settings (light, dark, light accessibility-text), About (light, dark, dark accessibility-text), and overlay states listening/transcribing/enhancing/done/error in light and dark. Findings: no high-confidence actionable HIG defects introduced or exposed by this PR; the change is confined to an internal comment with no rendering effect, so none of the reviewed screenshots are attributable to this diff, and no pre-existing issue in these surfaces is newly triggered or exposed. No UI action needed.
Scope check: The PR diff (Sources/OpenWritr/UpdateManager.swift) only rewrites a doc comment explaining why GitHubAttestationPolicy is not used for update verification. It contains no changes to any SwiftUI view, view model, or asset, so no rendered UI surface can be introduced or exposed by this change.
Surfaces reviewed for completeness against the fixed HIG criteria (native control semantics, keyboard/focus, accessibility names/state, semantic colors/text styles, Reduce Motion, loading/disabled/error/success states, and microphone/transcript/clipboard/provider-handoff/credential privacy):
Settings: light, dark, light plus accessibility (larger) text
About: light, dark, dark plus accessibility (larger) text
Recording overlay: listening, transcribing, enhancing, done, error (light and dark each)
Result: No high-confidence, actionable HIG defects introduced or exposed by this pull request were found. The change is a code-comment-only clarification with no rendered UI impact, and the screenshots reflect pre-existing production UI state rather than anything altered by this diff.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Moves the release trust boundary out of OpenWritr and into the public
trsdn/macos-notarization-brokerprofileopenwritr.Closes #58.
Depends on trsdn/macos-notarization-broker#69, which must merge first. That PR aligns the broker build/profile with OpenWritr, creates the AppUpdater alias, and ensures only the ZIP is attested while both DMG digests remain unattested for #31 compatibility.
Generated with GitHub Copilot.
Validation
swift build -c release -Xswiftc -warnings-as-errorsswiftlint lint --strictswift test(38 tests)bash -n scripts/*.shPYTHONPATH=scripts python3 -m unittest scripts/test_verify_broker_artifacts.py -v(4 tests)git diff --checkImpact
ghidentity, verifies numeric actor/repository/workflow identities and artifact digests, and no source workflow can access broker secrets.OpenWritr-{version}.dmg. Neither OpenWritr DMG may be attested; the ZIP may be.After this PR and broker PR #69 merge, these obsolete OpenWritr secrets can be deleted:
MACOS_CERTIFICATE,MACOS_CERTIFICATE_PWD,APPLE_ID,APPLE_TEAM_ID, andAPPLE_APP_PASSWORD.