Pulse/.github
rcourtman b74789fcc6 Add a non-publishing Apple signing and notary preflight
On 2 Oct 2026 v6.4.6-rc.1 failed notarization because the Apple developer
agreement was unsigned, about an hour into the release. The maintainer's
nightly release rehearsal now dispatches release-signing-preflight.yml from
main on a hosted macos-15 runner. It imports the Developer ID certificate
into a throwaway keychain, requires the identity to be valid and at least 30
days from expiry, signs and verifies a probe binary with a secure timestamp,
and reads the notary submission history with the release key, which Apple
refuses while an agreement is unsigned or the key is revoked. The four
checks are independent and each reports one titled outcome, so one night
names every broken credential. It builds, uploads and publishes nothing.
2026-10-02 19:24:29 +01:00
..
codeql/extensions/pulse-security-models Harden remaining CodeQL security boundaries 2026-07-09 19:46:40 +01:00
ISSUE_TEMPLATE Keep pre-release evidence visible and identify running images 2026-09-29 20:03:09 +01:00
scripts Stop demo diagnostics at failed tailnet readiness 2026-10-01 17:36:26 +01:00
workflows Add a non-publishing Apple signing and notary preflight 2026-10-02 19:24:29 +01:00
dependabot.yml Keep Vitest major upgrades coordinated 2026-09-27 10:10:45 +01:00
FUNDING.yml chore: add Ko-fi to funding options 2025-12-25 20:23:00 +00:00
PULL_REQUEST_TEMPLATE.md Port issue-first contribution policy to v6 docs 2026-05-01 20:28:11 +01:00
v6_rc_feedback_hub.md Rename user-facing RC wording to prerelease 2026-03-25 10:35:00 +00:00