Skip to content

Publish macOS releases from the Nix build - #2

Merged
jmecom merged 2 commits into
mainfrom
jm/nix-desktop-setup
Oct 9, 2026
Merged

jmecom merged 2 commits into
mainfrom
jm/nix-desktop-setup

Conversation

@jmecom

@jmecom jmecom commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Release builds used a separate setup from CI, and a manual run could build the selected branch while labeling the app with a different tag.

CI and releases now share the Nix macOS build, native module and signature checks, and ZIP packaging. Pushing a version tag builds that exact tag and publishes an Apple Silicon app ZIP, SHA-256 checksum, and generated release notes. Tags must match the package version; version suffixes create prereleases. The Nix installer is pinned to a commit SHA. Only the publish job has write permission, and reruns do not replace published assets. The release steps and current signing limitations are documented in CONTRIBUTING.md.

Checked with actionlint, valid and invalid version inputs, stable/prerelease publish arguments, and packaging, extraction, signature, and native module checks on the local portable app. The clean macOS CI job passed the full build, package checks, ZIP creation, and artifact upload. The installer is pinned to the exact SHA used by that successful build; CI is rerunning after the pin. The general check still fails on the two existing CSS audit violations on main.

Comment thread .github/workflows/build-macos.yml Fixed
Comment thread .github/workflows/build-macos.yml Fixed
@jmecom
jmecom marked this pull request as ready for review October 9, 2026 16:22
@jmecom
jmecom merged commit 09b8204 into main Oct 9, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants