Skip to content

fix(release): verify portable macOS signatures - #24

Merged
AlexMikhalev merged 1 commit into
mainfrom
codex/verify-portable-macos-signatures
Sep 15, 2026
Merged

AlexMikhalev merged 1 commit into
mainfrom
codex/verify-portable-macos-signatures

Conversation

@AlexMikhalev

Copy link
Copy Markdown
Contributor

Independent post-release validation found every downloaded macOS binary failed codesign verification despite passing immediately after signing. The release was returned to draft.\n\nThis adds fail-closed verification after temporary keychain deletion, after packaging, and after GitHub re-download, preventing publication unless signatures remain portable across every distribution boundary.\n\nValidation: actionlint and git diff --check pass.

@AlexMikhalev
AlexMikhalev merged commit ef89069 into main Sep 15, 2026
1 check failed
@AlexMikhalev
AlexMikhalev deleted the codex/verify-portable-macos-signatures branch September 15, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant