Skip to content

Release v0.0.1: provision protected credentials and publish #31

Description

@BunsDev

Release candidate

  • Source: main at f494e8ee320f538ac61a890164afdb023892752b (PR feat: show Coven sessions in the project rail #28 merged)
  • Version contract: v0.0.1 verified
  • Local unsigned Apple Silicon app and DMG built successfully
  • Curated GitHub and TestFlight notes generated
  • Full-history and publication-archive Gitleaks findings reviewed as code/vendor false positives

Repository safeguards complete

  • Public repository with secret scanning and push protection
  • Protected release environment with non-self Maintainers review
  • Deployment policies for main and v*
  • Protected main with required TypeScript/Rust and iOS checks
  • Active release-tag creation and immutable-tag rulesets
  • Homebrew tap updater workflow available

External credential handoff

Enter these interactively with gh secret set --env release --repo OpenCoven/psyche-build; never paste values into this issue:

  • APPLE_CERTIFICATE
  • APPLE_CERTIFICATE_PASSWORD
  • APPLE_SIGNING_IDENTITY
  • APPLE_ID
  • APPLE_PASSWORD
  • APPLE_DISTRIBUTION_CERTIFICATE
  • APPLE_DISTRIBUTION_CERTIFICATE_PASSWORD
  • APP_STORE_CONNECT_KEY_ID
  • APP_STORE_CONNECT_ISSUER_ID
  • APP_STORE_CONNECT_PRIVATE_KEY
  • APPLE_TEAM_ID
  • HOMEBREW_TAP_TOKEN

After all names are present, follow docs/RELEASE.md to re-verify unchanged main, create the signed annotated v0.0.1 tag, and obtain non-self release-environment approval. Do not create the tag before credential provisioning is complete.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions