Skip to content

[WRONG BRANCH] release: carry the macOS keyring signing fix to main - #6273

Merged
lidge-jun merged 1 commit into
mainfrom
codex/promote-main-2.73.0-signing
Sep 30, 2026
Merged

lidge-jun merged 1 commit into
mainfrom
codex/promote-main-2.73.0-signing

Conversation

@lidge-jun

Copy link
Copy Markdown
Owner

Summary

Carry #6271 (11782eedc3, sign the packaged macOS keyring addons before notarization) onto main so the 2.73.0 release can be retried. release.yml runs from this branch, and the first 2.73.0 attempt was refused by Apple notarization because Resources/keyring/*.node were unsigned (run 36648529039; nothing was published). The cherry-pick touches only .github/workflows/release.yml and its contract test; the version sources are unchanged.

Release authorization: the repository owner explicitly authorized the 2.73.0 release on 2026-09-30; this main merge runs on that authorization, as the #6265/#6266 promotions did.

Verification

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

…ion (#6271)

* fix(release): sign the packaged macOS keyring addons before notarization

Notarization rejected the 2.73.0 preview app: Resources/keyring/*.node, bundled
since #6161, were unsigned or ad-hoc and had no secure timestamp, and Tauri does
not sign files under Resources. Sign each darwin addon in place with the
Developer ID identity, hardened runtime and timestamp after the certificate
import and before tauri build, verify the result, and fail a real release that
lacks signing material.

* fix(release): match keyring signature fields without a pipe

(cherry picked from commit 11782ee)
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 30, 2026 00:27
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T00:28:29.567922Z 46c07c5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions github-actions Bot added the bug Something isn't working label Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 985b3118-a7a7-4566-a653-496079b6210c

📥 Commits

Reviewing files that changed from the base of the PR and between b825f4f and 46c07c5.

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • tests/ci-workflows/release-desktop-scripts.test.ts
 ______________________________________________________________________
< Your indentation suggests confidence. Your logic suggests otherwise. >
 ----------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lidge-jun
lidge-jun merged commit 569e3e7 into main Sep 30, 2026
14 of 15 checks passed
@lidge-jun
lidge-jun deleted the codex/promote-main-2.73.0-signing branch September 30, 2026 00:27
@github-actions github-actions Bot changed the title release: carry the macOS keyring signing fix to main [WRONG BRANCH] release: carry the macOS keyring signing fix to main Sep 30, 2026
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • wrong target branch (main); retarget to dev.

What to do

  • Retarget this PR to dev — all contributions go to dev.

Its title has been prefixed with [WRONG BRANCH].
Automatic draft conversion failed (token cannot change draft status). Please convert this pull request to a draft manually. The required enforce-target check will keep failing until every issue above is resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant