* Sign and notarize the macOS CLI binaries in releases
The install.sh archives for macOS shipped unsigned, so device-management
policies on work Macs blocked them. A release-signing-gated job now signs
and notarizes each darwin archive between dist's local and global builds,
rewriting its checksums so the installers and sha256.sum match.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* Harden CLI signing from review
Keep the called workflow from reporting skipped on dry runs, narrow its
token to read, pin the Developer ID requirement the updater checks, keep
notarization logs on failure, and correct the allow-dirty docs.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Add a `linked issue` check that fails PRs from forks unless the
description links an issue in this repository. PRs from branches in the
repo are exempt. It runs on pull_request_target so a fork cannot edit its
own check, and never checks out PR code.
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>