Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ concurrency:
jobs:
release:
name: Sign, notarize, and draft release
environment: release
runs-on: macos-15
timeout-minutes: 45

Expand Down Expand Up @@ -51,14 +52,13 @@ jobs:
env:
CERTIFICATE_P12_BASE64: ${{ secrets.APPLE_DEVELOPER_ID_CERTIFICATE_P12_BASE64 }}
CERTIFICATE_PASSWORD: ${{ secrets.APPLE_DEVELOPER_ID_CERTIFICATE_PASSWORD }}
KEYCHAIN_PASSWORD: ${{ secrets.APPLE_KEYCHAIN_PASSWORD }}
shell: bash
run: |
set -euo pipefail
: "${CERTIFICATE_P12_BASE64:?Missing APPLE_DEVELOPER_ID_CERTIFICATE_P12_BASE64 secret}"
: "${CERTIFICATE_PASSWORD:?Missing APPLE_DEVELOPER_ID_CERTIFICATE_PASSWORD secret}"
: "${KEYCHAIN_PASSWORD:?Missing APPLE_KEYCHAIN_PASSWORD secret}"

KEYCHAIN_PASSWORD="$(openssl rand -base64 32)"
keychain="$RUNNER_TEMP/pinative-signing.keychain-db"
certificate="$RUNNER_TEMP/developer-id.p12"
echo "$CERTIFICATE_P12_BASE64" | base64 --decode > "$certificate"
Expand Down
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,12 @@
# Changelog

## 2026-09-02


### Changed

- Scoped official release credentials to a dedicated GitHub environment and replaced the stored temporary-keychain password with a fresh per-run value.

## 2026-09-01


Expand Down
13 changes: 10 additions & 3 deletions docs/releasing.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,11 @@ when access is no longer required.

## GitHub Actions configuration

Create a GitHub Actions environment named `release`. The official release job
declares this environment so signing and notarization credentials are unavailable
to pull-request and routine CI jobs. Restrict the environment to protected release
tags matching `v*`; optionally require maintainer approval before deployment.

Add the following **Actions repository variable**. It identifies the signing
team and is not confidential, but keeping it out of the repository lets a fork
or new maintainer configure its own release identity.
Expand All @@ -49,19 +54,21 @@ or new maintainer configure its own release identity.
| --- | --- |
| `APPLE_TEAM_ID` | Apple Team ID that owns the Developer ID certificate. |

Add the following **Actions secrets** to the repository. Never add their values
to tracked files, workflow logs, issue comments, or release notes.
Add the following **environment secrets** to the `release` environment. Never add
their values to tracked files, workflow logs, issue comments, or release notes.

| Secret | Value |
| --- | --- |
| `APPLE_DEVELOPER_ID_CERTIFICATE_P12_BASE64` | Base64 encoding of the Developer ID `.p12` file. |
| `APPLE_DEVELOPER_ID_CERTIFICATE_PASSWORD` | Password used when exporting that `.p12`. |
| `APPLE_KEYCHAIN_PASSWORD` | Newly generated, high-entropy temporary-keychain password. |
| `APPLE_NOTARY_API_KEY_ID` | App Store Connect API Key ID. |
| `APPLE_NOTARY_API_ISSUER_ID` | App Store Connect API Issuer ID. |
| `APPLE_NOTARY_API_KEY_P8_BASE64` | Base64 encoding of the downloaded `.p8` private key. |
| `POSTHOG_PROJECT_API_KEY` | PostHog `phc_` project token used by official builds for opt-in product analytics. |

The workflow generates a fresh high-entropy password for its temporary keychain
during every run; no keychain-password secret is stored.

On macOS, copy a file’s Base64 value without saving another credential file:

```sh
Expand Down
Loading