Skip to content

[Meta] Prepare wider desktop distribution #7

Description

@iamnbutler

Track the remaining work for wider desktop distribution: verifying a published upgrade on another Mac, moving downloads to a custom domain, third-party notices, and completing a source review and secret scan of the repository, which is already public.

Signed canary builds are published through the Sparkle feed described in the desktop update procedure. A release can build any clean pushed lane, so a published build contains its pinned source revision; consult its release manifest/workflow and the feed for its version and included changes rather than this issue.

Release

Related release operations work (not a distribution gate): #167 — show release phases and notarization submissions while a build runs.

Migrated from TODO.md.

Activity

  1. iamnbutler commented on Oct 7, 2026

    @iamnbutler
    ContributorAuthor

    Related release operations work: #197 adds a GitHub release with the signed DMG for every shipped desktop channel/version; R2 remains the Sparkle update host.

  2. iamnbutler commented on Oct 7, 2026

    @iamnbutler
    ContributorAuthor

    Published Ace canary 0.0.21 from b35cbbe8d0c3e7ebf9c674e35aa7f5346210bddc after merging #209, #211, and the version bump #212. Includes the Cmd+Shift+A Agentation shortcut and the four desktop sizing adjustments.

    Release workflow 37667437911 passed type/format/lint checks, signing, both notarizations, artifact upload, GitHub/R2/feed publication, and credential cleanup. The Ace channel downloaded and verified the source revision and manifest checksum. Local Gatekeeper accepted both DMG and contained app as Notarized Developer ID; stapled-ticket checks and deep/strict code signature verification passed, and the contained app reports 0.0.21.

    GitHub's uploaded-asset SHA-256 and a fresh public R2 download both match b6a235807d9144c2de4071a37018260a8d481e48c0275878d9871910329a4da9. The public feed exactly matches the signed CI artifact and serves Cache-Control: no-store; the versioned DMG serves immutable cache headers. Native source UI behavior was verified before release in #211. This run did not install the canary or perform the separate two-Mac acceptance in #39.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions