Use internal Apple codesign action - #14437
Merged
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Production signing depends on an internal action that could not be independently inspected or tested end-to-end.
Review tier: Balanced
Findings: 1
Open findings (1)
What changed in this PR
Replaces the deprecated external Apple codesigning action with GitHub’s internal Node 24 action while preserving the existing workflow contract.
Changes:
- Updates the pinned codesigning action reference.
- Retains existing inputs, outputs, conditions, and step ID.
| File | Description |
|---|---|
.github/workflows/deployment.yml |
Uses the internal Apple codesigning action. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
niik
approved these changes
Sep 14, 2026
cverorg
pushed a commit
to CVERInc/clikae
that referenced
this pull request
Sep 14, 2026
… (P2-2) With review_requested gone the whitelist was commented|reviewed, but the body was still the last string "body" anywhere on the timeline page. An Approve with no text is a reviewed event whose body is not a string, so the scan fell through to the previous comment: [commented by zed "hey @me", reviewed by carol body:null] printed "mention by carol". Real schema, checked read-only on 2026-09-14: cli/cli#14437's approve review is "body":null, #14429's is "body":"" (both with `user`, no `actor`). The null shape is pinned, de-identified but with its real key order and nesting, in tests/fixtures/github-timeline-approve-null-body.json. The page is now split by _wg_timeline_events, a quote-, escape- and depth-aware awk splitter that also returns each element's own top-level body (empty for null/absent). A `},{` inside a string or a nested labels:[{..},{..}] no longer splits an element, so the whole-page body fallback is gone. Cross-checked against Python's json on three real timeline pages (element count, event order, null/empty/non-empty body per element all match); gawk, mawk and busybox awk give byte-identical output; 64KB page in 12 ms. Tests: body:null (fixture) and no body field -> "review by carol", red before / green after; control with nested objects and `},{` around the selected review's own "@me" -> "mention by carol".
pull Bot
pushed a commit
to Bettdatt/cli
that referenced
this pull request
Sep 15, 2026
This reverts commit 38316c1.
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Relates to #14411.
Description
The deployment workflow uses an external action to configure an App Store Connect API key. This replaces it with the internal
github/setup-apple-codesignaction pinned to verified Node 24 commit9ba41e90aff70dea04ae487b776f98ee5efd610f.The existing step name, condition, ID, inputs, outputs, and downstream behavior are unchanged.
How did you test this change?
Not tested end-to-end because this step requires production deployment credentials. I parsed
.github/workflows/deployment.ymlsuccessfully and verified that the branch diff is clean and limited to the single action reference change.I also compared the pinned action revisions. Their
action.ymlinput and output definitions are identical; the runtime changes from Node 20 to Node 24. The source blobs for the entrypoint, asset dispatch, and App Store Connect API key implementation are byte-identical between the current external pin and the proposed internal pin.This is an internal link but here is the diff between
nodeselector/setup-apple-codesignandgithub/setup-apple-codesign: https://github.com/github/setup-apple-codesign/compare/309922bbe4c7277c477635e68d3a1af52d8ad06b...9ba41e90aff70dea04ae487b776f98ee5efd610fKey points
github/setup-apple-codesignfor the sameapp-store-connect-api-keyasset type and consumes the same three outputs in release workflows. Those workflows pin an older Node 20 revision, so they demonstrate the internal action's contract and production usage rather than validating this specific Node 24 revision.Authorship and follow-up
Who wrote this:
Who answers review comments: