Skip to content

Use internal Apple codesign action - #14437

Merged
williammartin merged 2 commits into
trunkfrom
williammartin-apple-codesign-action
Sep 14, 2026
Merged

williammartin merged 2 commits into
trunkfrom
williammartin-apple-codesign-action

Conversation

@williammartin

@williammartin williammartin commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Relates to #14411.

Description

The deployment workflow uses an external action to configure an App Store Connect API key. This replaces it with the internal github/setup-apple-codesign action pinned to verified Node 24 commit 9ba41e90aff70dea04ae487b776f98ee5efd610f.

The existing step name, condition, ID, inputs, outputs, and downstream behavior are unchanged.

How did you test this change?

Not tested end-to-end because this step requires production deployment credentials. I parsed .github/workflows/deployment.yml successfully and verified that the branch diff is clean and limited to the single action reference change.

I also compared the pinned action revisions. Their action.yml input and output definitions are identical; the runtime changes from Node 20 to Node 24. The source blobs for the entrypoint, asset dispatch, and App Store Connect API key implementation are byte-identical between the current external pin and the proposed internal pin.

This is an internal link but here is the diff between nodeselector/setup-apple-codesign and github/setup-apple-codesign: https://github.com/github/setup-apple-codesign/compare/309922bbe4c7277c477635e68d3a1af52d8ad06b...9ba41e90aff70dea04ae487b776f98ee5efd610f

Key points

  • The replacement remains pinned to a full, verified commit SHA.
  • The proposed commit reports successful TypeScript tests, GitHub Actions tests, distribution checks, linting, and CodeQL checks in the action repository.
  • GitHub Mobile uses github/setup-apple-codesign for the same app-store-connect-api-key asset type and consumes the same three outputs in release workflows. Those workflows pin an older Node 20 revision, so they demonstrate the internal action's contract and production usage rather than validating this specific Node 24 revision.

Authorship and follow-up

Who wrote this:

  • A human wrote it.
  • An agent wrote it under close human direction.
  • An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

  • @williammartin will read and reply directly. Name the account.
  • An agent will draft replies and @username will read them before they are posted.
  • Nobody has explicitly committed to replying.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 14, 2026 09:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Production signing depends on an internal action that could not be independently inspected or tested end-to-end.

Review tier: Balanced
Findings: 1 Low severity

Open findings (1)
What changed in this PR

Replaces the deprecated external Apple codesigning action with GitHub’s internal Node 24 action while preserving the existing workflow contract.

Changes:

  • Updates the pinned codesigning action reference.
  • Retains existing inputs, outputs, conditions, and step ID.
File Description
.github/​workflows/​deployment.yml Uses the internal Apple codesigning action.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/deployment.yml
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@williammartin
williammartin marked this pull request as ready for review September 14, 2026 09:59
@williammartin
williammartin requested a review from a team as a code owner September 14, 2026 09:59
@williammartin
williammartin requested a review from niik September 14, 2026 09:59
@williammartin
williammartin merged commit 38316c1 into trunk Sep 14, 2026
16 checks passed
@williammartin
williammartin deleted the williammartin-apple-codesign-action branch September 14, 2026 14:26
cverorg pushed a commit to CVERInc/clikae that referenced this pull request Sep 14, 2026
… (P2-2)

With review_requested gone the whitelist was commented|reviewed, but the
body was still the last string "body" anywhere on the timeline page. An
Approve with no text is a reviewed event whose body is not a string, so
the scan fell through to the previous comment: [commented by zed "hey @me",
reviewed by carol body:null] printed "mention by carol".

Real schema, checked read-only on 2026-09-14: cli/cli#14437's approve
review is "body":null, #14429's is "body":"" (both with `user`, no
`actor`). The null shape is pinned, de-identified but with its real key
order and nesting, in tests/fixtures/github-timeline-approve-null-body.json.

The page is now split by _wg_timeline_events, a quote-, escape- and
depth-aware awk splitter that also returns each element's own top-level
body (empty for null/absent). A `},{` inside a string or a nested
labels:[{..},{..}] no longer splits an element, so the whole-page body
fallback is gone. Cross-checked against Python's json on three real
timeline pages (element count, event order, null/empty/non-empty body
per element all match); gawk, mawk and busybox awk give byte-identical
output; 64KB page in 12 ms.

Tests: body:null (fixture) and no body field -> "review by carol", red
before / green after; control with nested objects and `},{` around the
selected review's own "@me" -> "mention by carol".
pull Bot pushed a commit to Bettdatt/cli that referenced this pull request Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants