ci: added macOS release signing and Homebrew automation to CI
- Added macOS CI signing and notarization steps when APPLE_* secrets are configured. - Added strict darwin verification checks to reject ad-hoc signatures and run smoke tests. - Added Homebrew formula publishing from release assets with SHA-256 checksums. - Added helper scripts for signing secret upload, entitlements, and release workflows.
This commit is contained in:
@@ -373,6 +373,8 @@ jobs:
|
||||
permissions:
|
||||
contents: read
|
||||
id-token: write
|
||||
env:
|
||||
MACOS_SIGNING: ${{ secrets.APPLE_CERTIFICATE_P12 != '' && secrets.APPLE_API_KEY != '' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: oven-sh/setup-bun@v2
|
||||
@@ -402,6 +404,19 @@ jobs:
|
||||
env:
|
||||
RELEASE_TARGETS: ${{ matrix.target_id }}
|
||||
run: bun run ci:release:build-binaries
|
||||
- name: Sign and notarize macOS binary (Developer ID)
|
||||
# Replaces the ad-hoc signature with a Developer ID + hardened-runtime
|
||||
# one (+JIT/library-validation entitlements; omp dlopens its
|
||||
# runtime-extracted native addon, which has a different Team ID) and
|
||||
# notarizes. Auto-skips until the APPLE_* secrets are configured.
|
||||
if: matrix.platform == 'darwin' && env.MACOS_SIGNING == 'true'
|
||||
env:
|
||||
APPLE_CERTIFICATE_P12: ${{ secrets.APPLE_CERTIFICATE_P12 }}
|
||||
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
|
||||
APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }}
|
||||
APPLE_API_ISSUER_ID: ${{ secrets.APPLE_API_ISSUER_ID }}
|
||||
APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }}
|
||||
run: bash scripts/ci-macos-sign.sh "${{ matrix.binary_path }}"
|
||||
# Windows binary is cross-built on Linux, so we have no Windows runner
|
||||
# to smoke it on. Cross-build correctness is verified via the napi
|
||||
# entry-point exports (see build-native action) and the bun
|
||||
@@ -463,6 +478,8 @@ jobs:
|
||||
runs-on: macos-14
|
||||
permissions:
|
||||
contents: read
|
||||
env:
|
||||
MACOS_SIGNING: ${{ secrets.APPLE_CERTIFICATE_P12 != '' && secrets.APPLE_API_KEY != '' }}
|
||||
steps:
|
||||
- name: Download published macOS arm64 binary
|
||||
run: |
|
||||
@@ -470,9 +487,22 @@ jobs:
|
||||
chmod +x omp-darwin-arm64
|
||||
- name: Verify published macOS arm64 binary
|
||||
run: |
|
||||
codesign -dv ./omp-darwin-arm64
|
||||
codesign -dvvv ./omp-darwin-arm64
|
||||
codesign --verify --strict --verbose=4 ./omp-darwin-arm64
|
||||
runtime_dir="$(mktemp -d)"
|
||||
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" ./omp-darwin-arm64 --version
|
||||
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" ./omp-darwin-arm64 --smoke-test
|
||||
- name: Assert signed release is not ad-hoc
|
||||
if: env.MACOS_SIGNING == 'true'
|
||||
run: |
|
||||
if codesign -dvvv ./omp-darwin-arm64 2>&1 | grep -qE "flags=.*adhoc|Signature=adhoc"; then
|
||||
echo "published binary is still ad-hoc signed (Developer ID signing did not run)" >&2
|
||||
exit 1
|
||||
fi
|
||||
# Gatekeeper assessment: a notarized Developer ID binary is accepted.
|
||||
# Informational — a bare (unstapled) Mach-O relies on the online ticket
|
||||
# lookup, so surface the result without gating the release on it.
|
||||
spctl -a -t exec -vv ./omp-darwin-arm64 || echo "spctl non-zero (expected for unstapled bare binary; ticket served online)"
|
||||
|
||||
release-npm:
|
||||
if: ${{ needs.gate.outputs.is-release == 'true' && !cancelled() &&
|
||||
@@ -513,3 +543,44 @@ jobs:
|
||||
# publisher for the package (or on a first publish).
|
||||
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||
run: bun run ci:release:publish
|
||||
|
||||
# Regenerate the Homebrew tap formula (can1357/homebrew-tap) from the freshly
|
||||
# published release assets and push it. Depends only on release-github (the
|
||||
# release and its binaries must exist). No-ops when HOMEBREW_TAP_DEPLOY_KEY is
|
||||
# unset, so a release never blocks on tap access.
|
||||
release_brew:
|
||||
if: ${{ needs.gate.outputs.is-release == 'true' && !cancelled() &&
|
||||
needs['release-github'].result == 'success' }}
|
||||
needs: [gate, release-github]
|
||||
runs-on: ubuntu-22.04
|
||||
env:
|
||||
HAS_TAP_KEY: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY != '' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
if: env.HAS_TAP_KEY == 'true'
|
||||
- uses: oven-sh/setup-bun@v2
|
||||
if: env.HAS_TAP_KEY == 'true'
|
||||
with:
|
||||
bun-version: "1.3"
|
||||
- name: Check out the Homebrew tap
|
||||
if: env.HAS_TAP_KEY == 'true'
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: can1357/homebrew-tap
|
||||
ssh-key: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY }}
|
||||
path: homebrew-tap
|
||||
- name: Regenerate and push the formula
|
||||
if: env.HAS_TAP_KEY == 'true'
|
||||
env:
|
||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
run: |
|
||||
bun scripts/ci-update-brew-formula.ts "${{ needs.gate.outputs.release-tag }}" --out homebrew-tap/Formula/omp.rb
|
||||
cd homebrew-tap
|
||||
if git diff --quiet -- Formula/omp.rb; then
|
||||
echo "formula already up to date for ${{ needs.gate.outputs.release-tag }}"
|
||||
exit 0
|
||||
fi
|
||||
git -c user.name="github-actions[bot]" \
|
||||
-c user.email="41898282+github-actions[bot]@users.noreply.github.com" \
|
||||
commit -m "omp ${{ needs.gate.outputs.release-tag }}" -- Formula/omp.rb
|
||||
git push origin HEAD:main
|
||||
|
||||
Reference in New Issue
Block a user