Skip to content

feat: import pinned Nextcloud appstore workflow reference - #2

Merged
vitormattos merged 1 commit into
mainfrom
feat/import-nextcloud-appstore-reference
Sep 20, 2026
Merged

vitormattos merged 1 commit into
mainfrom
feat/import-nextcloud-appstore-reference

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Add the first immutable upstream reference used to design reusable Nextcloud app release automation.

Source:

  • repository: nextcloud/.github
  • commit: cf6248d5ef28a328cde764daf80bc5fae4705ade
  • file: workflow-templates/appstore-build-publish.yml
  • SHA-256: 4710d78c576abd1c875d799770f67262988119404d58d379656f5932872fcba8

The file is deliberately vendored under upstream/vendor/, not exposed under templates/: it remains an upstream design reference, not a LibreCode workflow safe for consumption.

Security review identified follow-up design changes before reuse, including checksum verification for downloaded tooling, stronger secret handling, and separation of build/sign/publish privileges.

This PR is stacked on #1; merge #1 first.

Signed-off-by: Vitor Mattos <vitor@php.rio>
@vitormattos
vitormattos force-pushed the feat/import-nextcloud-appstore-reference branch from cd8a437 to f16f05f Compare September 20, 2026 01:51
@vitormattos
vitormattos merged commit a4f1176 into main Sep 20, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant