mirror of
https://github.com/alphaXiv/OpenResearch.git
synced 2026-10-02 09:44:51 +08:00
* Sign and notarize the macOS CLI binaries in releases The install.sh archives for macOS shipped unsigned, so device-management policies on work Macs blocked them. A release-signing-gated job now signs and notarizes each darwin archive between dist's local and global builds, rewriting its checksums so the installers and sha256.sum match. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Harden CLI signing from review Keep the called workflow from reporting skipped on dry runs, narrow its token to read, pin the Developer ID requirement the updater checks, keep notarization logs on failure, and correct the allow-dirty docs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
34 lines
1.6 KiB
TOML
34 lines
1.6 KiB
TOML
[workspace]
|
|
members = ["cargo:."]
|
|
|
|
# Config for 'dist'
|
|
[dist]
|
|
# The preferred dist version to use in CI (Cargo.toml SemVer syntax)
|
|
cargo-dist-version = "0.32.0"
|
|
# CI backends to support
|
|
ci = "github"
|
|
# Mark only publishing builds and verify every packaged binary before hosting.
|
|
github-build-setup = "../build-setup.yml"
|
|
# Sign and notarize the macOS archives before the global build checksums them.
|
|
local-artifacts-jobs = ["./sign-macos-cli"]
|
|
# release.yml is hand-edited (custom-sign-macos-cli needs build-local-artifacts),
|
|
# so dist skips it; see macos/DISTRIBUTION.md before changing dist config.
|
|
allow-dirty = ["ci"]
|
|
# Verify packaged binaries and source CI before publishing.
|
|
global-artifacts-jobs = ["./verify-build-channel", "./telemetry-contract", "./ci"]
|
|
# The installers to generate for each app
|
|
installers = ["shell", "powershell"]
|
|
# Target platforms to build apps for (Rust target-triple syntax)
|
|
targets = ["aarch64-apple-darwin", "x86_64-apple-darwin", "aarch64-unknown-linux-musl", "x86_64-unknown-linux-musl", "x86_64-pc-windows-msvc"]
|
|
# Path that installers should place binaries in
|
|
install-path = "CARGO_HOME"
|
|
# Whether to install an updater program
|
|
install-updater = false
|
|
# Trigger releases via workflow_dispatch instead of tag push. The tag is
|
|
# created implicitly when the GitHub Release is published at the end, so no
|
|
# workflow ever pushes a tag — which lets release-on-bump.yml dispatch
|
|
# releases with the default GITHUB_TOKEN (workflow_dispatch is exempt from
|
|
# GitHub's "GITHUB_TOKEN events don't trigger workflows" rule; tag pushes are
|
|
# not). No PAT or extra secret required.
|
|
dispatch-releases = true
|