Repository navigation
ci: generate and publish signed Sparkle appcast in release workflow - #27
Merged
Merged
Conversation
Wire the SPARKLE_PRIVATE_KEY secret into the release pipeline so each
release produces an EdDSA-signed appcast and commits it back to main.
- .github/workflows/release.yml: add "Generate Sparkle appcast" step that
runs update-appcast.sh and asserts the sparkle:edSignature and
download URL landed in the output; add "Publish Sparkle appcast" step
that checks out main, commits appcast.xml only when it changed, and
pushes to main as github-actions[bot]
- scripts/update-appcast.sh: feed the private key to generate_appcast
over stdin via --ed-key-file - when SPARKLE_PRIVATE_KEY is set, so the
key never appears in process arguments or is written to disk
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe release workflow now generates, validates, and conditionally publishes a signed Sparkle appcast. The appcast script accepts ChangesSparkle appcast release flow
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant ReleaseWorkflow
participant update_appcast_sh
participant generate_appcast
participant MainBranch
ReleaseWorkflow->>update_appcast_sh: invoke with SPARKLE_PRIVATE_KEY
update_appcast_sh->>generate_appcast: pass signing key via standard input
generate_appcast-->>ReleaseWorkflow: produce signed appcast.xml
ReleaseWorkflow->>ReleaseWorkflow: validate signature and DMG URL
ReleaseWorkflow->>MainBranch: commit and push changed appcast.xml
Possibly related PRs
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wire the SPARKLE_PRIVATE_KEY secret into the release pipeline so each
release produces an EdDSA-signed appcast and commits it back to main.
runs update-appcast.sh and asserts the sparkle:edSignature and
download URL landed in the output; add "Publish Sparkle appcast" step
that checks out main, commits appcast.xml only when it changed, and
pushes to main as github-actions[bot]
over stdin via --ed-key-file - when SPARKLE_PRIVATE_KEY is set, so the
key never appears in process arguments or is written to disk
Summary by CodeRabbit
New Features
Bug Fixes