Skip to content

ci(release): isolate signing from publishing - #71

Merged
trsdn merged 9 commits into
mainfrom
ci/release-isolation
Sep 22, 2026
Merged

trsdn merged 9 commits into
mainfrom
ci/release-isolation

Conversation

@trsdn

@trsdn trsdn commented Sep 22, 2026

Copy link
Copy Markdown
Owner

Summary

  • bind all release builds to the triggering immutable tag
  • isolate signing/notarization in the tag-restricted release environment with read-only repository access
  • hand verified artifacts to a separate draft-release job with the only contents: write permission
  • keep Apple credentials out of draft creation, smoke testing, and publication
  • align the release checklist with the canonical tag-triggered five-asset pipeline

Security

Manual recovery must run with --ref vx.y.z; the workflow rejects branch refs, checks out refs/tags/${tag}, verifies HEAD against the tag commit, and uses gh release create --verify-tag. The update DMG remains unattested and no AppUpdater attestation policy is added.

Validation

  • swift build -c release -Xswiftc -warnings-as-errors
  • swiftlint lint --strict
  • swift test
  • actionlint .github/workflows/release.yml .github/workflows/smoke-test.yml
  • bash -n scripts/setup_notarization.sh

Closes #62

Part of #58. The release environment and v* deployment restriction are configured. The five existing repository secrets must still be re-entered as environment secrets before their repository-level copies can be removed.

Refactor the tagged release pipeline around environment-scoped Apple credentials and verified artifact handoff, and align the maintainer release documentation with the automated path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Reject non-tag manual dispatches before the release environment is used, checkout and verify the fully qualified tag commit, and prevent GitHub CLI from creating a missing tag.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI lite review requested due to automatic review settings September 22, 2026 08:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical least-privilege and tag-to-commit binding issues remain, along with a release checklist filename mismatch.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity

Open (3)
What changed in this PR

This PR hardens the tag-triggered macOS release pipeline by isolating signing credentials and release permissions.

Changes:

  • Separates signing, draft creation, smoke testing, and publication.
  • Restricts credentials to the release environment.
  • Updates release documentation, asset guidance, and runner versions.
File Summary
scripts/​setup_notarization.sh Configures environment-scoped secrets.
RELEASE_CHECKLIST.md Documents the canonical release workflow.
README.md Updates release assets and credential documentation.
AGENTS.md Documents environment-scoped credentials.
.github/​workflows/​smoke-test.yml Pins the smoke-test runner.
.github/​workflows/​release.yml Implements the separated release pipeline and tag validation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/release.yml
Comment thread .github/workflows/release.yml
Comment thread .github/workflows/release.yml Outdated
Reject moved-tag races at checkout and draft mutation, and smoke-test the immutable workflow artifact with read-only repository access.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 09:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved tag-mutability and stale-asset findings could publish incorrect or unverified release contents.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (3)

Comment thread .github/workflows/release.yml
Reuse a fail-closed remote tag resolver before both draft mutation and final publication so a tag moved during smoke testing cannot be published.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 09:29

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical workflow issues remain in smoke-test artifact selection and mutable action pinning, with additional release validation concerns.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 3 High severity

Open (3)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Pin release smoke-test download action to a commit SHA

.github/​workflows/​smoke-test.yml:59

This newly added artifact download uses a mutable major tag. Pin it to a full commit SHA with a version comment, consistent with the repository's action-lock entries, so the release smoke-test code cannot change when the upstream tag moves.

Comment thread .github/workflows/release.yml
Comment thread .github/workflows/release.yml
Comment thread .github/workflows/smoke-test.yml Outdated
Pin the release artifact supply chain to reviewed action commits and select reusable smoke-test downloads from the artifact input rather than the caller event.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 09:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive release workflow warrants final human review, and the checklist contains an unresolved artifact-path mismatch.

Review effort: Lite
Findings: 1 Low severity

Open (1)
Resolved since last review (3)

Comment thread RELEASE_CHECKLIST.md Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 09:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The release workflow must prevent stale extra assets, and the documented recovery and setup procedures need correction.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .github/workflows/release.yml
Fail closed on unexpected draft assets before upload, verify the exact five assets after upload, and recheck the contract immediately before publication.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 10:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The asset-contract verification fails on an empty draft, blocking the documented first-release upload path.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread scripts/verify_release_asset_contract.sh Outdated
Keep the empty line from a no-assets GitHub response from becoming a failing while-loop status under set -e.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4ea0580f-655c-457e-9b12-dd7e8dc1dfe5
Copilot AI review requested due to automatic review settings September 22, 2026 10:34

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Fix the release changelog lookup for version suffixes before approval.

Review effort: Lite
Findings: None

Resolved since last review (1)

@trsdn
trsdn merged commit 0e154ce into main Sep 22, 2026
9 checks passed
@trsdn
trsdn deleted the ci/release-isolation branch September 22, 2026 11:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(release): align the checklist with the automated release pipeline

2 participants