Skip to content

fix(ci): gate releases on native artifact checks - #138

Merged
sadiksaifi merged 3 commits into
mainfrom
fix/verify-release-artifacts
Sep 20, 2026
Merged

sadiksaifi merged 3 commits into
mainfrom
fix/verify-release-artifacts

Conversation

@sadiksaifi

Copy link
Copy Markdown
Owner

Description

Prevent corrupt, incorrectly targeted, invalidly signed, or non-launching binaries from reaching GitHub releases, Homebrew, or npm. The tag-only release workflow now validates the exact archives on native runners before any publication step can start.

These jobs run only for version tags in .github/workflows/release.yml; normal pull-request and branch CI remains unchanged.

What is the purpose of this pull request?

  • Bug fix
  • New Feature
  • Documentation update
  • Code refactoring
  • Performance improvement
  • Other

Changes

  • Build all six platform archives once and transfer them through GitHub Actions artifacts.
  • Verify Linux ARM64/x64 binaries on native Ubuntu runners.
  • Verify Windows ARM64/x64 PE architecture, version, and startup on native Windows runners.
  • Re-sign macOS ARM64/x64 binaries on native macOS runners, preserve Bun's entitlements/runtime flags, and strictly verify the final packaged archives.
  • Require exact native architecture and ai-git --version checks for every platform.
  • Assemble checksums only from verified archives.
  • Gate GitHub release creation, Homebrew updates, and npm publication on every native verification job.
  • Keep write permission only on the publication job; build and verification jobs remain read-only.
  • Use current major-version tags for GitHub Actions.

Testing

  • Tested on macOS version: 27.0
  • Tested with different input types
  • Tested in pipe chains
  • Ran actionlint .github/workflows/release.yml successfully.
  • Validated workflow YAML and ran git diff --check.
  • Confirmed normal CI configuration is unchanged and release verification remains tag-only.
  • Re-signed, repackaged, re-extracted, strictly verified, and executed the published v3.0.2 macOS ARM64 archive locally.
  • Independently reviewed runner labels, artifact paths, native architecture checks, job dependencies, and permissions.

Screenshots

Not applicable.

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes

@sadiksaifi sadiksaifi left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

P1: npm bypasses the verified workflow artifacts

  • Location: .github/workflows/release.yml:450
  • Failure: The native jobs verify and assemble release-artifacts, but publish-npm ignores that immutable in-run artifact and downloads from the GitHub Release instead. This repository currently has immutable releases disabled, and softprops/action-gh-release defaults to overwriting same-named assets. A release-asset replacement or full rerun can therefore make npm consume bytes that are different from the artifact that passed this workflow's native gates.
  • Impact: npm can publish binaries that were not the exact verified inputs used for the GitHub/Homebrew release, and retry paths can leave channels serving different bytes under one version.
  • Fix: Download release-artifacts directly with actions/download-artifact in publish-npm and verify checksums.txt before packaging. Separately enable GitHub immutable releases or otherwise fail closed instead of overwriting existing release assets.

Comment thread .github/workflows/release.yml Outdated
@sadiksaifi

Copy link
Copy Markdown
Owner Author

npm bypasses the verified workflow artifacts.

Source: #138 (review)

FIXED

  • Fixed npm artifact identity and release overwrite behavior in 91a69c0.
  • npm now downloads the in-run release-artifacts artifact and verifies checksums.txt. Release publication fails closed when the tag already has a release, disables asset overwrites, and rejects unmatched files.

Verified:

  • actionlint .github/workflows/release.yml
  • git diff --check

@sadiksaifi
sadiksaifi merged commit 697182d into main Sep 20, 2026
1 check passed
@sadiksaifi
sadiksaifi deleted the fix/verify-release-artifacts branch September 20, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant