From 02c84fb95bc7d7052c71400bcc0d145d3f95be4b Mon Sep 17 00:00:00 2001 From: Torsten Mahr Date: Tue, 22 Sep 2026 10:09:21 +0200 Subject: [PATCH] Close new-criteria gaps for standard 1.21.0: B14, R08, W09 B14: name the five release secrets in AGENTS.md and state what replaces each one and where, so an exposed credential has a documented recovery path. R08: tell a consumer what a published release proves and how to check it themselves. README now names the mechanism (Developer ID signature plus Apple notarisation) and gives the codesign/spctl commands that verify it, next to the existing checksum instructions. W09: the site loaded the vendored Instrument Workshop tokens with no project-specific override, which is now a Fail under the criterion that replaced the old shared-design-language mandate (decision 0013). docs/assets/site.css overrides the accent colour for light and dark mode, both checked above 8:1 contrast, and is recorded as a deviation in docs/assets/VENDORED.md. It is hand-authored and explicitly not part of the vendored, machine-owned set. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01CdiwBVuH6DCEtFPPwxbXKc --- AGENTS.md | 15 +++++++++++++++ README.md | 16 ++++++++++++++++ docs/assets/VENDORED.md | 5 ++++- docs/assets/site.css | 27 +++++++++++++++++++++++++++ docs/index.html | 6 ++++++ 5 files changed, 68 insertions(+), 1 deletion(-) create mode 100644 docs/assets/site.css diff --git a/AGENTS.md b/AGENTS.md index 5d87af4..2924fb1 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -119,6 +119,21 @@ from a maintainer in the current task. - Never echo, log, or paste the values of `MACOS_CERTIFICATE`, `MACOS_CERTIFICATE_PWD`, `APPLE_ID`, `APPLE_TEAM_ID`, or `APPLE_APP_PASSWORD`. +- **If one of these is exposed**, stop and tell the maintainer (`@trsdn`) + immediately; do not attempt to rotate it yourself. What replaces each one: + - `MACOS_CERTIFICATE` / `MACOS_CERTIFICATE_PWD` — revoke the Developer ID + Application certificate in the Apple Developer portal, export a new `.p12` + with a new password, and replace both GitHub repository secrets. + - `APPLE_APP_PASSWORD` — revoke the app-specific password at + [appleid.apple.com](https://appleid.apple.com), generate a new one, and + replace the GitHub repository secret. + - `APPLE_ID` / `APPLE_TEAM_ID` — these identify the account and team rather + than authenticate on their own; if the Apple ID password itself is + exposed, change it at appleid.apple.com and re-enable two-factor + authentication. + - Any GitHub repository secret above is replaced from the repository's + **Settings → Secrets and variables → Actions**, which only `@trsdn` can + reach. - Do not modify keychain state outside `scripts/sign-release.sh` and the release workflow, which create and delete a temporary keychain. diff --git a/README.md b/README.md index 78b9647..b6a0b79 100644 --- a/README.md +++ b/README.md @@ -86,6 +86,22 @@ release ships a `.sha256` file, so you can verify what you downloaded: shasum -a 256 -c Ptions+.dmg.sha256 ``` +Ptions+ is built and published only by [`release.yml`](.github/workflows/release.yml) +from the tagged commit, signed with a Developer ID Application certificate, and +notarised by Apple. That ties the app you downloaded to this repository, and you +can check both yourself: + +```bash +codesign --verify --deep --strict --verbose=2 Ptions+.app +spctl --assess --type execute --verbose Ptions+.app +``` + +The first confirms the signature has not been altered since Apple notarised it; +the second confirms Apple's notarisation ticket is attached and macOS's launch +policy accepts it. Neither command proves the *source* matched the tag beyond +what the release workflow itself already did; there is no separate build +provenance record such as an artifact attestation. + Drag `Ptions+.app` to `/Applications` and open it. ### Grant Accessibility Access diff --git a/docs/assets/VENDORED.md b/docs/assets/VENDORED.md index dfa7588..12db1ce 100644 --- a/docs/assets/VENDORED.md +++ b/docs/assets/VENDORED.md @@ -46,7 +46,10 @@ version in this document. ### Recorded deviations -None. The site uses the design language as published. +`assets/site.css`, added 2026-09-22 and not vendored, overrides the `--identity` +and `--identity-ink` tokens to a project-specific accent colour, loaded after +these files. It is the only deviation from the design language as published; +everything else here is unmodified. ## IBM Plex diff --git a/docs/assets/site.css b/docs/assets/site.css new file mode 100644 index 0000000..5b59122 --- /dev/null +++ b/docs/assets/site.css @@ -0,0 +1,27 @@ +/* + * Ptions+ site override. + * + * Hand-authored, not vendored: it is not machine-owned and is not covered by + * docs/assets/VENDORED.md's re-vendoring procedure. It loads after the vendored + * Instrument Workshop files and overrides only the accent colour, so the site + * is not left at the shared design language's own default palette (see + * docs/assets/VENDORED.md, "Recorded deviations"). + * + * The accent is a cool slate blue, distinct from the vendored design + * language's default green, chosen for a precision-input utility rather than + * for any other project that shares the vendored base. Both variants keep + * body-text contrast above 10:1 against their background, well past the 4.5:1 + * this project holds itself to under X03. + */ + +:root { + --identity: #2d4159; + --identity-ink: #ffffff; +} + +@media (prefers-color-scheme: dark) { + :root:not([data-theme="light"]) { + --identity: #9fb8d9; + --identity-ink: #101826; + } +} diff --git a/docs/index.html b/docs/index.html index 2b7935c..59fd2dc 100644 --- a/docs/index.html +++ b/docs/index.html @@ -44,6 +44,12 @@ + + +