Repository navigation
fix(release): sign and notarize macOS downloads - #9
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 14, 2026, 11:13 AM ET / 15:13 UTC. ClawSweeper reviewWhat this changesReplace tag-triggered releases with a pinned signing and notarization workflow, enforce macOS 12 deployment targets, and document release and download verification. Merge readiness⛔ Blocked before merge - 1 item remains The signing fix remains useful: current main still uses the unsigned release pipeline, and no merged replacement was found. No blocking patch defect was identified; owner authorship and repository policy also preclude automatic closure. Priority: P2 Review scores
Verification
How this fits togetherblucli’s release pipeline turns tagged Go source into downloadable archives and Homebrew updates. This change adds Apple signing and notarization between building binaries and publishing verified assets. flowchart LR
A[Manual release request] --> B[Protected source and CI checks]
B --> C[Build six platform binaries]
C --> D[Check macOS deployment targets]
D --> E[Sign and notarize macOS binaries]
E --> F[Independent artifact verification]
F --> G[GitHub release and Homebrew update]
Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Adopt the owner-proposed dispatch workflow while preserving existing download contracts, and verify the first signed release through the documented Gatekeeper and Homebrew checks. Do we have a high-confidence way to reproduce the issue? No: source confirms that current main lacks the proposed signing pipeline, but this review did not reproduce Gatekeeper rejection with a quarantined v0.1.6 download. Is this the best way to solve the issue? Yes: the pinned shared workflow supplies the signing and verification stages while the caller preserves existing archives and enforces the stated macOS minimum. AGENTS.md: found, but no applicable review policy affected this item. Codex review notes: model internal, reasoning medium; reviewed against 5cc25b387e9f. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Prepare v0.1.7 with the macOS Developer ID signing and notarization fix as the release highlight. Finalize the dated changelog section and set the source version to 0.1.7 so source installs report the same version as release binaries. The signed release migration landed in #9. Validation: CLI/application tests and a source-built `blu --version` returning `0.1.7`; independent P0–P2 review. Release publication will use the shared workflow after exact-head CI passes.
macOS release binaries were only ad-hoc signed, so direct downloads failed Gatekeeper. Replace the tag-triggered publisher with the shared Go CLI release workflow pinned to v1.9.0 (
f613cbfed2b043159c850c353e7facb8c89833b0), using Peter Steinberger's personal Developer ID identity and Apple notarization.The workflow owns the annotated tag, immutable release payload, independent Intel/Apple Silicon verification, checksum-bound publication, and the
steipete/homebrew-taphandoff. Existing archive names,checksums.txt,LICENSE/README.mdmembers, and thebluexecutable stay compatible. Signing credentials are confined to the shared signing job.Build on macOS and check every Darwin Mach-O deployment target after GoReleaser builds it. Both architectures must record macOS 12.0; regression tests reject newer/older targets, malformed commands, wrong platforms, and mixed slices. CI exercises this same build configuration without signing secrets. Document setup, release dispatch, and verification, and record the user-facing fix in Unreleased.
Validation: actionlint; GoReleaser configuration check; Python target-gate regression tests; Go race tests; golangci-lint; six-platform snapshot build with Go 1.26.8; independent P0–P2 review. Repository prerequisites are configured: protected main and Actions closeout PR permissions.