Repository navigation
Publish macOS releases from the Nix build - #2
Merged
Merged
Conversation
jmecom
marked this pull request as ready for review
October 9, 2026 16:22
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release builds used a separate setup from CI, and a manual run could build the selected branch while labeling the app with a different tag.
CI and releases now share the Nix macOS build, native module and signature checks, and ZIP packaging. Pushing a version tag builds that exact tag and publishes an Apple Silicon app ZIP, SHA-256 checksum, and generated release notes. Tags must match the package version; version suffixes create prereleases. The Nix installer is pinned to a commit SHA. Only the publish job has write permission, and reruns do not replace published assets. The release steps and current signing limitations are documented in CONTRIBUTING.md.
Checked with
actionlint, valid and invalid version inputs, stable/prerelease publish arguments, and packaging, extraction, signature, and native module checks on the local portable app. The clean macOS CI job passed the full build, package checks, ZIP creation, and artifact upload. The installer is pinned to the exact SHA used by that successful build; CI is rerunning after the pin. The general check still fails on the two existing CSS audit violations on main.