Repository navigation
fix(release): select notarization credential keychains - #281
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 1, 2026, 12:38 AM ET / 04:38 UTC. ClawSweeper reviewWhat this changesAdds an optional credential-keychain setting for macOS desktop and server notarization, with documentation and argument-forwarding regression coverage. Merge readiness✅ Ready for maintainer review This remains useful: current main and v0.6.0 lack explicit credential-keychain selection. No concrete patch defect was found, and GitHub confirms the author has repository admin access. Priority: P2 Review scores
Verification
How this fits togetherClickClack’s macOS release scripts submit signed desktop and server archives to Apple for notarization. The shared submission helper selects credentials and checks Apple’s acceptance before artifact verification continues. flowchart TD
A[Signed desktop or server archive] --> C[Shared notarization helper]
B[Credential profile and optional keychain] --> C
C --> D[Apple notarization submission]
D --> E{Submission accepted}
E -->|Yes| F[Artifact verification]
E -->|No| G[Release stops]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep explicit keychain selection optional in the shared submission helper so headless release hosts can use managed credentials while existing release commands retain their defaults. Do we have a high-confidence way to reproduce the issue? Not applicable: this adds explicit credential-keychain selection. Source inspection establishes the missing setting on main; the reported Apple run was not independently reproduced. Is this the best way to solve the issue? Yes: extending the existing shared submission helper is the narrowest approach and preserves the current command when the setting is absent. AGENTS.md: found, but no applicable review policy affected this item. Codex review notes: model internal, reasoning medium; reviewed against bc909123584d. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Allow macOS release automation to read notarization credentials from a configured keychain when the login keychain is locked.
NOTARYTOOL_KEYCHAIN_PATHpasses the selected path tonotarytool --keychainfor both desktop and server notarization.Five focused signing tests pass, including a subprocess regression test for a credential-keychain path containing spaces. A Foundation-signed CLI was accepted by Apple using the explicit keychain, and its online
notarizedrequirement was verified. Independent P0–P2 review is clean.