Skip to content

ci: fail release early when signing secrets are missing - #36

Merged
fly1d merged 1 commit into
mainfrom
codex/release-preflight
Aug 18, 2026
Merged

ci: fail release early when signing secrets are missing#36
fly1d merged 1 commit into
mainfrom
codex/release-preflight

Conversation

@fly1d

@fly1d fly1d commented Aug 18, 2026

Copy link
Copy Markdown
Owner

Summary

  • add an early release preflight that checks all six Apple signing secrets are present without printing values
  • make the macOS build depend on the preflight so missing credentials fail before reserving a macOS runner
  • document the behavior in the release guide

Verification

  • git diff --check
  • local shell checks for empty and complete secret sets
  • required CI, browser smoke, desktop, CodeQL, and analyze checks

This does not publish artifacts or change signing behavior.

@fly1d

fly1d commented Aug 18, 2026

Copy link
Copy Markdown
Owner Author

Maintainer review: release preflight is correct and scoped. It checks all six Apple signing secrets before reserving a macOS runner, reports only missing names, and the required CI, browser smoke, desktop, CodeQL, and analysis checks are passing. No blocking findings.

@fly1d
fly1d merged commit ef24614 into main Aug 18, 2026
5 checks passed
@fly1d
fly1d deleted the codex/release-preflight branch August 18, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant