Skip to content

Commit 5e73c28

Browse files
committed
ci(mas): isolate App Store signing workflow
- split unsigned builds from privileged App Store signing - restrict signing credentials to the mas-signing environment - sign bundles explicitly with a fixed entitlement policy - embed and verify the provisioning profile before packaging - add package signature checks and signing material cleanup - pin third-party actions and enforce least-privilege permissions - cancel obsolete runs and restrict signing to release refs - stabilize artifact names with seven-character commit SHAs
1 parent cbaea9b commit 5e73c28

2 files changed

Lines changed: 545 additions & 101 deletions

File tree

‎.github/workflows/build.yml‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,12 @@ jobs:
142142
# an expression expanded inside `run:` is textual substitution.
143143
BUILD_MODE_INPUT: ${{ github.event.inputs.build_mode }}
144144
run: |
145-
echo "SHORT_SHA=$(git rev-parse --short HEAD)" >> $GITHUB_ENV
145+
# A fixed slice of GITHUB_SHA, not `git rev-parse --short`: git's
146+
# abbreviation length scales with object count, so it yields 7 here
147+
# (actions/checkout is shallow by default) and 8 in a full clone.
148+
# Pinning it keeps artifact names stable and identical across
149+
# platforms.
150+
echo "SHORT_SHA=${GITHUB_SHA:0:7}" >> $GITHUB_ENV
146151
147152
# Identifier the artifacts are named after. On Linux the runner label
148153
# ("ubuntu-24.04-arm") is the wrong thing to publish: the build host's
@@ -975,7 +980,7 @@ jobs:
975980
# --short HEAD` abbreviates to in this repository, so the macOS names
976981
# line up with the Linux and Windows artifacts.
977982
{
978-
echo "short_sha=${GITHUB_SHA:0:8}"
983+
echo "short_sha=${GITHUB_SHA:0:7}"
979984
echo "build_type_lower=${BUILD_TYPE_LOWER}"
980985
} >> "$GITHUB_OUTPUT"
981986

0 commit comments

Comments
 (0)