Files
OpenResearch/dist-workspace.toml
Myles AndersonandClaude Opus 5.5 de469a3f44 OR-319 Sign and notarize the macOS CLI binaries in releases (#427)
* Sign and notarize the macOS CLI binaries in releases

The install.sh archives for macOS shipped unsigned, so device-management
policies on work Macs blocked them. A release-signing-gated job now signs
and notarizes each darwin archive between dist's local and global builds,
rewriting its checksums so the installers and sha256.sum match.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Harden CLI signing from review

Keep the called workflow from reporting skipped on dry runs, narrow its
token to read, pin the Developer ID requirement the updater checks, keep
notarization logs on failure, and correct the allow-dirty docs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-23 15:21:50 -07:00

34 lines
1.6 KiB
TOML

[workspace]
members = ["cargo:."]
# Config for 'dist'
[dist]
# The preferred dist version to use in CI (Cargo.toml SemVer syntax)
cargo-dist-version = "0.32.0"
# CI backends to support
ci = "github"
# Mark only publishing builds and verify every packaged binary before hosting.
github-build-setup = "../build-setup.yml"
# Sign and notarize the macOS archives before the global build checksums them.
local-artifacts-jobs = ["./sign-macos-cli"]
# release.yml is hand-edited (custom-sign-macos-cli needs build-local-artifacts),
# so dist skips it; see macos/DISTRIBUTION.md before changing dist config.
allow-dirty = ["ci"]
# Verify packaged binaries and source CI before publishing.
global-artifacts-jobs = ["./verify-build-channel", "./telemetry-contract", "./ci"]
# The installers to generate for each app
installers = ["shell", "powershell"]
# Target platforms to build apps for (Rust target-triple syntax)
targets = ["aarch64-apple-darwin", "x86_64-apple-darwin", "aarch64-unknown-linux-musl", "x86_64-unknown-linux-musl", "x86_64-pc-windows-msvc"]
# Path that installers should place binaries in
install-path = "CARGO_HOME"
# Whether to install an updater program
install-updater = false
# Trigger releases via workflow_dispatch instead of tag push. The tag is
# created implicitly when the GitHub Release is published at the end, so no
# workflow ever pushes a tag — which lets release-on-bump.yml dispatch
# releases with the default GITHUB_TOKEN (workflow_dispatch is exempt from
# GitHub's "GITHUB_TOKEN events don't trigger workflows" rule; tag pushes are
# not). No PAT or extra secret required.
dispatch-releases = true