Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions .github/github-app.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,11 @@ instructions: |

The rules that are most often broken:

1. Never add a build-attestation policy to UpdateManager and never attest the
update DMG. It crashes shipped apps (see #31).
2. Never publish a release, create or move tags, or change repository settings.
1. Never add a build-attestation policy to UpdateManager and never attest
either OpenWritr DMG. They share one digest and can crash shipped apps
(see #31).
2. Never publish a release, create or move tags, dispatch the notarization
broker, run the publication handoff, or change repository settings.
3. Never log transcript text, audio, prompts, or API keys.

Validate with `swift build -c release -Xswiftc -warnings-as-errors`, `swiftlint lint --strict`, and `swift test` before proposing any change.
Expand Down
9 changes: 9 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,3 +34,12 @@ jobs:

- name: Test
run: swift test

- name: Validate release tooling
run: |
bash -n scripts/*.sh
bash scripts/test_publish_broker_release.sh
PYTHONPATH=scripts python3 -m unittest discover -s scripts -p 'test_*.py'
python3 -m py_compile \
scripts/extract_release_notes.py \
scripts/verify_broker_artifacts.py
Loading
Loading