ci: harden release custody gate#8
Conversation
Signed-off-by: gchahal1982 <108035922+gchahal1982@users.noreply.github.com>
7605594 to
b5fe96f
Compare
|
2026-05-20 release custody follow-up pushed to this branch (
|
Signed-off-by: gchahal1982 <108035922+gchahal1982@users.noreply.github.com>
103eabb to
0d288cc
Compare
|
DCO/sign-off follow-up: amended the custody commit with sign-off and force-with-lease pushed the same scoped changes. Current PR head is |
|
2026-05-20 custody follow-up:
The PR still needs review/merge and a protected hosted release workflow run; Windows EV/HSM/PFX signing custody and Microsoft package identity evidence remain separate blockers. |
Signed-off-by: gchahal1982 <108035922+gchahal1982@users.noreply.github.com>
Signed-off-by: gchahal1982 <108035922+gchahal1982@users.noreply.github.com>
|
2026-05-20 managed Windows signing follow-up:
This does not close the Windows release blocker by itself; actual EV/PFX/Azure signing custody and Microsoft package identity evidence are still required before hosted release execution and winget submission. |
Summary
Validation
go run github.com/rhysd/actionlint/cmd/actionlint@latest .github/workflows/release.ymlbash -n scripts/sign-and-notarize-macos.sh scripts/sign-linux.sh scripts/generate-checksums.shscripts/sign-windows.ps1Remaining external blockers