Skip to content

ci: inline Sparkle keys and verify bundled public key in release workflow - #28

Merged
lonewolfyx merged 1 commit into
mainfrom
ci/verify-bundled-sparkle-key
Jul 13, 2026
Merged

lonewolfyx merged 1 commit into
mainfrom
ci/verify-bundled-sparkle-key

Conversation

@lonewolfyx

@lonewolfyx lonewolfyx commented Jul 13, 2026 •

Copy link
Copy Markdown
Member

Summary by CodeRabbit

  • Bug Fixes
    • Improved release verification by ensuring the app’s update-signing key matches the configured release key.
    • Release builds now fail automatically when signing-key configuration is inconsistent.

@lonewolfyx
lonewolfyx merged commit 9b7e1a7 into main Jul 13, 2026
1 check was pending
@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 8d639e37-7762-4c23-9ef1-224cb64c93c6

📥 Commits

Reviewing files that changed from the base of the PR and between c99eefb and 166d5e2.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

📝 Walkthrough

Walkthrough

The release workflow now exposes Sparkle keys at job scope, verifies the app bundle’s SUPublicEDKey against the configured public key, and uses the job-level private key during appcast generation.

Changes

Sparkle release verification

Layer / File(s) Summary
Release key configuration and verification
.github/workflows/release.yml
The release job defines Sparkle keys for subsequent steps, validates SUPublicEDKey from Info.plist, fails on a mismatch, and removes redundant secret injection and validation from appcast generation.

Estimated code review effort: 2 (Simple) | ~10 minutes

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/verify-bundled-sparkle-key

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lonewolfyx
lonewolfyx deleted the ci/verify-bundled-sparkle-key branch July 13, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant