Skip to content

ci: generate and publish signed Sparkle appcast in release workflow - #27

Merged
lonewolfyx merged 1 commit into
mainfrom
ci/sparkle-appcast-publish
Jul 13, 2026
Merged

lonewolfyx merged 1 commit into
mainfrom
ci/sparkle-appcast-publish

Conversation

@lonewolfyx

@lonewolfyx lonewolfyx commented Jul 13, 2026 •

Copy link
Copy Markdown
Member

Wire the SPARKLE_PRIVATE_KEY secret into the release pipeline so each
release produces an EdDSA-signed appcast and commits it back to main.

  • .github/workflows/release.yml: add "Generate Sparkle appcast" step that
    runs update-appcast.sh and asserts the sparkle:edSignature and
    download URL landed in the output; add "Publish Sparkle appcast" step
    that checks out main, commits appcast.xml only when it changed, and
    pushes to main as github-actions[bot]
  • scripts/update-appcast.sh: feed the private key to generate_appcast
    over stdin via --ed-key-file - when SPARKLE_PRIVATE_KEY is set, so the
    key never appears in process arguments or is written to disk

Summary by CodeRabbit

  • New Features

    • Release builds now automatically generate and publish signed Sparkle appcast metadata.
    • Update notifications can securely reference the latest release asset with verified EdDSA signatures.
  • Bug Fixes

    • Added validation to ensure generated appcasts contain the expected signature and release download URL.

  Wire the SPARKLE_PRIVATE_KEY secret into the release pipeline so each
  release produces an EdDSA-signed appcast and commits it back to main.

  - .github/workflows/release.yml: add "Generate Sparkle appcast" step that
    runs update-appcast.sh and asserts the sparkle:edSignature and
    download URL landed in the output; add "Publish Sparkle appcast" step
    that checks out main, commits appcast.xml only when it changed, and
    pushes to main as github-actions[bot]
  - scripts/update-appcast.sh: feed the private key to generate_appcast
    over stdin via --ed-key-file - when SPARKLE_PRIVATE_KEY is set, so the
    key never appears in process arguments or is written to disk
@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 764ba76d-22e4-4a1f-8a44-5b198c397992

📥 Commits

Reviewing files that changed from the base of the PR and between 6a8563b and 73fe937.

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • scripts/update-appcast.sh

📝 Walkthrough

Walkthrough

The release workflow now generates, validates, and conditionally publishes a signed Sparkle appcast. The appcast script accepts SPARKLE_PRIVATE_KEY and passes it to generate_appcast when provided.

Changes

Sparkle appcast release flow

Layer / File(s) Summary
Appcast signing support
.github/workflows/release.yml, scripts/update-appcast.sh
The script documents SPARKLE_PRIVATE_KEY and conditionally uses it for EdDSA signing while preserving unsigned generation when absent.
Release appcast generation and publication
.github/workflows/release.yml
The workflow validates the generated signature and release URL, then commits and pushes appcast.xml to main only when changed.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseWorkflow
  participant update_appcast_sh
  participant generate_appcast
  participant MainBranch
  ReleaseWorkflow->>update_appcast_sh: invoke with SPARKLE_PRIVATE_KEY
  update_appcast_sh->>generate_appcast: pass signing key via standard input
  generate_appcast-->>ReleaseWorkflow: produce signed appcast.xml
  ReleaseWorkflow->>ReleaseWorkflow: validate signature and DMG URL
  ReleaseWorkflow->>MainBranch: commit and push changed appcast.xml
Loading

Possibly related PRs

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/sparkle-appcast-publish

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lonewolfyx
lonewolfyx merged commit bc54424 into main Jul 13, 2026
1 check was pending
@lonewolfyx
lonewolfyx deleted the ci/sparkle-appcast-publish branch July 13, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant