Skip to content

feat(installer): unsigned double-click installers attached to every release - #1975

Merged
Alan-TheGentleman merged 4 commits into
mainfrom
feat/double-click-installers
Oct 9, 2026
Merged

Alan-TheGentleman merged 4 commits into
mainfrom
feat/double-click-installers

Conversation

@Alan-TheGentleman

@Alan-TheGentleman Alan-TheGentleman commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Refs #1700

Summary

A person who does not use a terminal can now install Gentle Shell like a classic desktop installer: download one file, double-click it, follow the steps in the browser.

  • Every release gets three unsigned downloads with stable names (releases/latest/download/<name>): gentle-shell-installer-macos.zip (Install Gentle Shell.command), gentle-shell-installer-windows.zip (Install Gentle Shell.cmd) and gentle-shell-installer-linux.tar.gz (install-gentle-shell.sh), plus gentle-shell-installers-SHA256SUMS.txt.
  • Each launcher runs the bundled bootstrap, which opens the existing installation wizard. No git, clone or typed command; ~100 KB, no dependencies (the wizard imports only node: modules).
  • The README now leads Get started with "Easiest: download and double-click", and explains the expected first-run warnings of unsigned files: macOS Gatekeeper (Open Anyway in Privacy & Security), Windows SmartScreen (More info → Run anyway), extracting the zip first, and checking SHA-256.

Changes

File Change
scripts/build-installer-bundles.mjs New builder: wizard files + import/file-URL closure as real files, per-OS launchers (CRLF .cmd), archives, checksums. Launchers report a failed bootstrap.
.github/workflows/publish.yml New installers job: needs: publish, same verified commit (github.sha), persist-credentials: false, contents: write only here, uploads with the publish job's verified tag (needs.publish.outputs.tag), --clobber. npm publication is unaffected by its failure.
README.md, docs/install-wizard.md Download table, unsigned warnings and how to continue, fallback to the checkout path, recovery note (gh run rerun <id> --failed).
tests/installer-bundles.test.ts, tests/package-manifest.test.ts Bundle closure, archive layout, exec bits, CRLF, self-sufficient extraction, workflow guarantees.

Test plan

  • tests/installer-bundles.test.ts tests/package-manifest.test.ts tests/verify-package-files.test.ts: 78 pass, 0 fail. pnpm run typecheck: no regressions. Full pnpm test: only the three failures already on main.
  • Built locally: macOS zip extracted with ditto keeps Install Gentle Shell.command executable; sh -n on the launcher passes.
  • Independent verifier: PASS S1–S4, no blockers. Native review (risk, readability, reliability) approved; its advisories are addressed in ac91c0b24 (after the reviewed candidate).
  • actionlint: not available locally.
  • Not verified: real double-click on clean macOS/Windows/Linux, the Gatekeeper/SmartScreen screens, and the job on a real runner. The download links start working with the next stable release.

Summary by CodeRabbit

  • New Features
    • Download double-click installers for macOS, Windows, and Linux directly from releases.
    • Preview the planned changes before confirming installation. The installer may temporarily download Node.js and pnpm to prepare the preview.
    • Verify installer downloads using the provided SHA-256 checksums.
  • Documentation
    • Added platform-specific launch instructions, guidance for operating-system security warnings, and details about using the installer from a checkout.
    • Clarified that installers are unsigned and that preview and testing coverage may be limited.

@Alan-TheGentleman Alan-TheGentleman added the type:feature New feature label Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 44dd10eb-7560-4b63-9f25-cf7d8532384b

📥 Commits

Reviewing files that changed from the base of the PR and between be2869b and ac91c0b.


📒 Files selected for processing (7)
  • .github/workflows/publish.yml
  • README.md
  • docs/install-wizard.md
  • odd/tasks/double-click-installers.md
  • scripts/build-installer-bundles.mjs
  • tests/installer-bundles.test.ts
  • tests/package-manifest.test.ts

 ______________
< Bugs begone! >
 --------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Alan-TheGentleman
Alan-TheGentleman merged commit 1e475d0 into main Oct 9, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:feature New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant