7 Commits
Author SHA1 Message Date
Myles AndersonandClaude Opus 5.5 de469a3f44 OR-319 Sign and notarize the macOS CLI binaries in releases (#427)
* Sign and notarize the macOS CLI binaries in releases

The install.sh archives for macOS shipped unsigned, so device-management
policies on work Macs blocked them. A release-signing-gated job now signs
and notarizes each darwin archive between dist's local and global builds,
rewriting its checksums so the installers and sha256.sum match.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Harden CLI signing from review

Keep the called workflow from reporting skipped on dry runs, narrow its
token to read, pin the Developer ID requirement the updater checks, keep
notarization logs on failure, and correct the allow-dirty docs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 15:21:50 -07:00
Myles AndersonandClaude Opus 5.5 13d7c1fd44 Require fork PRs to link an issue (#425)
Add a `linked issue` check that fails PRs from forks unless the
description links an issue in this repository. PRs from branches in the
repo are exempt. It runs on pull_request_target so a fork cannot edit its
own check, and never checks out PR code.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 12:57:56 -07:00
Daniel Kim 718b171496 Use simulated PR merges without a merge queue (#294) 2026-09-07 16:10:59 -07:00
Daniel Kim d23b057d34 Validate merge queue candidates with required CI checks (#293) 2026-09-07 15:59:58 -07:00
Daniel Kim 1e5a2fec84 Gate release publishing on CI and flush restored SSH public keys (#292) 2026-09-07 15:44:42 -07:00
Daniel Kim 505b272317 refactor: keep research state local (#202) 2026-08-17 16:28:46 -07:00
Daniel Kim 69027830f8 Add repository-specific agent instructions (#174)
* Add repository agent instructions

* Slim repository agent guidance
2026-08-10 15:56:08 -07:00