Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -119,6 +119,21 @@ from a maintainer in the current task.
- Never echo, log, or paste the values of `MACOS_CERTIFICATE`,
`MACOS_CERTIFICATE_PWD`, `APPLE_ID`, `APPLE_TEAM_ID`, or
`APPLE_APP_PASSWORD`.
- **If one of these is exposed**, stop and tell the maintainer (`@trsdn`)
immediately; do not attempt to rotate it yourself. What replaces each one:
- `MACOS_CERTIFICATE` / `MACOS_CERTIFICATE_PWD` — revoke the Developer ID
Application certificate in the Apple Developer portal, export a new `.p12`
with a new password, and replace both GitHub repository secrets.
- `APPLE_APP_PASSWORD` — revoke the app-specific password at
[appleid.apple.com](https://appleid.apple.com), generate a new one, and
replace the GitHub repository secret.
- `APPLE_ID` / `APPLE_TEAM_ID` — these identify the account and team rather
than authenticate on their own; if the Apple ID password itself is
exposed, change it at appleid.apple.com and re-enable two-factor
authentication.
- Any GitHub repository secret above is replaced from the repository's
**Settings → Secrets and variables → Actions**, which only `@trsdn` can
reach.
- Do not modify keychain state outside `scripts/sign-release.sh` and the
release workflow, which create and delete a temporary keychain.

Expand Down
16 changes: 16 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,22 @@ release ships a `.sha256` file, so you can verify what you downloaded:
shasum -a 256 -c Ptions+.dmg.sha256
```

Ptions+ is built and published only by [`release.yml`](.github/workflows/release.yml)
from the tagged commit, signed with a Developer ID Application certificate, and
notarised by Apple. That ties the app you downloaded to this repository, and you
can check both yourself:

```bash
codesign --verify --deep --strict --verbose=2 Ptions+.app
spctl --assess --type execute --verbose Ptions+.app
```

The first confirms the signature has not been altered since Apple notarised it;
the second confirms Apple's notarisation ticket is attached and macOS's launch
policy accepts it. Neither command proves the *source* matched the tag beyond
what the release workflow itself already did; there is no separate build
provenance record such as an artifact attestation.

Drag `Ptions+.app` to `/Applications` and open it.

### Grant Accessibility Access
Expand Down
5 changes: 4 additions & 1 deletion docs/assets/VENDORED.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,10 @@ version in this document.

### Recorded deviations

None. The site uses the design language as published.
`assets/site.css`, added 2026-09-22 and not vendored, overrides the `--identity`
and `--identity-ink` tokens to a project-specific accent colour, loaded after
these files. It is the only deviation from the design language as published;
everything else here is unmodified.

## IBM Plex

Expand Down
27 changes: 27 additions & 0 deletions docs/assets/site.css
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
/*
* Ptions+ site override.
*
* Hand-authored, not vendored: it is not machine-owned and is not covered by
* docs/assets/VENDORED.md's re-vendoring procedure. It loads after the vendored
* Instrument Workshop files and overrides only the accent colour, so the site
* is not left at the shared design language's own default palette (see
* docs/assets/VENDORED.md, "Recorded deviations").
*
* The accent is a cool slate blue, distinct from the vendored design
* language's default green, chosen for a precision-input utility rather than
* for any other project that shares the vendored base. Both variants keep
* body-text contrast above 10:1 against their background, well past the 4.5:1
* this project holds itself to under X03.
*/

:root {
--identity: #2d4159;
--identity-ink: #ffffff;
}

@media (prefers-color-scheme: dark) {
:root:not([data-theme="light"]) {
--identity: #9fb8d9;
--identity-ink: #101826;
}
}
6 changes: 6 additions & 0 deletions docs/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,12 @@
<link rel="stylesheet" href="assets/core.tokens.css">
<link rel="stylesheet" href="assets/instrument-workshop.css">

<!--
Ptions+ accent override, hand-authored and not vendored.
See assets/site.css and assets/VENDORED.md, "Recorded deviations".
-->
<link rel="stylesheet" href="assets/site.css">

<!-- Structured Data -->
<script type="application/ld+json">
{
Expand Down
Loading