Skip to content

fix(ci): sign V1 macOS CLI before release publishing - #51015

Open
opencode-agent[bot] wants to merge 1 commit into
devfrom
v1-macos-cli-sign
Open

opencode-agent[bot] wants to merge 1 commit into
devfrom
v1-macos-cli-sign

Conversation

@opencode-agent

Copy link
Copy Markdown
Contributor

Problem

V1 release macOS CLI assets fail codesign --verify (including v1.18.32). Bun cross-compilation on Linux modifies the executable after its bundled signature was created, and V1 distributes it without signing the finished bytes. This also affects publisher-based application whitelisting.

Change

  • Sign arm64, x64, and x64-baseline V1 CLI binaries on a macOS runner with our Developer ID certificate, hardened runtime, and Bun-compatible entitlements; verify all three and smoke-test arm64.
  • Repack and upload only signed macOS release archives. The Linux build no longer uploads its unsigned macOS archives in CI.
  • Replace unsigned macOS build artifacts with signed binaries and zips before publishing npm packages and generating Homebrew checksums.

The existing #48428 uses ad-hoc signing, which restores code-signature validity but provides no Developer ID identity for publisher-based whitelists. This PR uses the V2 Developer ID approach. Related: #46313.

Validation

  • actionlint passes with only the repository’s pre-existing Blacksmith runner-label warnings ignored.
  • On macOS, re-signed a downloaded V1 1.18.32 arm64 binary with the proposed hardened-runtime entitlements using a local ad-hoc test identity; strict codesign verification passed, opencode --version printed 1.18.32, and the repacked zip contained the identical binary.
  • plutil -lint passes for the entitlements file; git diff --check passes.

Developer ID signing and end-to-end release publishing require a release workflow run after review; this PR does not cut a release. Package typecheck was unavailable in the clean worktree without installed dependencies.

Requested by: @rekram1-node (Aiden via Slack)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant