Skip to content

Verify the final Year View release ZIP - #13

Open
peterjthomson wants to merge 4 commits into
masterfrom
codex/release-pipeline-checks
Open

peterjthomson wants to merge 4 commits into
masterfrom
codex/release-pipeline-checks

Conversation

@peterjthomson

@peterjthomson peterjthomson commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Year View's release instructions checked the exported app, while the download users install is a ZIP. Add a Year View-specific verifier that extracts the final ZIP into a temporary directory and checks bundle layout, identifier/version, Developer ID signing, the stapled ticket and Gatekeeper acceptance on a quarantined copy.

Keep the existing Xcode archive/export, notarization and app-stapling commands. Replace the shared release protocol with Year View's own ZIP and native calendar walkthrough instructions; remove cross-repository synchronization claims. There are no changes to signing identities, credentials, App Store configuration or application code.

Validation:

  • The prior verifier rejects ZIP-only input because it requires a DMG.
  • The new verifier passes against the signed, notarized Year View 1.4.0 release ZIP.
  • Two Python tests cover valid/malformed layouts, multiple apps, unsafe paths and missing input; these run in the existing macOS CI test job.
  • Shell syntax and diff checks pass. Xcode application tests were not rerun for this tooling-only change.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 70d0d73. Configure here.

Comment thread scripts/release/mac_artifacts.py Outdated
run('xattr', '-w', 'com.apple.quarantine', '0081;00000000;ReleaseVerification;', str(copied))
run('spctl', '--assess', '--type', 'open', '--context', 'context:primary-signature', str(copied))
mount = work / 'mount'
run('hdiutil', 'attach', '-nobrowse', '-readonly', '-mountpoint', str(mount), str(copied))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DMG mount point is never created

High Severity

verify() attaches a DMG at work / 'mount' with hdiutil attach -mountpoint, but that directory is never created. hdiutil requires an existing empty mount point, so every DMG verification fails before the copied app is checked. ZIP-only Year View runs do not hit this path; shared Ledger and Marktext DMG gates do.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 70d0d73. Configure here.

@peterjthomson peterjthomson changed the title Verify ZIP releases and share native release checks Verify the final Year View release ZIP Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant