Skip to content

ci: add release-v3.yml workflow for signed v3 binary releases - #5318

Merged
taliesin-ai merged 5 commits into
masterfrom
agent/engineer-linux/0908911e
Jun 29, 2026
Merged

taliesin-ai merged 5 commits into
masterfrom
agent/engineer-linux/0908911e

Conversation

@leaanthony

@leaanthony leaanthony commented May 3, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds .github/workflows/release-v3.yml — a GitHub Actions workflow that:

  • Triggers on any tag push matching v3.* (and supports workflow_dispatch for dry-run / manual test builds)
  • Builds the wails3 CLI binary for all 5 required targets using CGO_ENABLED=0 for portable, statically-linked binaries:
    • linux/amd64 — ubuntu-latest runner
    • linux/arm64 — ubuntu-24.04-arm (native ARM64 runner)
    • darwin/amd64 — macos-latest runner
    • darwin/arm64 — macos-latest runner (GOARCH=arm64)
    • darwin universal — lipo -create merge of the two darwin binaries
    • windows/amd64 — windows-latest runner
  • Signs all three macOS binaries with codesign --options=runtime --timestamp
  • Notarizes all three macOS binaries via xcrun notarytool submit --wait
  • Attaches every binary to the GitHub Release created for the tag

Required GitHub Actions secrets

Configure these in Settings → Secrets and variables → Actions before pushing a v3.* tag:

Secret Description
APPLE_SIGNING_CERT Base64-encoded Developer ID Application certificate (.p12)
APPLE_CERT_PASSWORD Password protecting the .p12 file
APPLE_SIGNING_IDENTITY Full identity string, e.g. Developer ID Application: Wails (XXXXXXXXXX)
APPLE_TEAM_ID 10-character Apple Developer Team ID
APPLE_NOTARIZE_USER Apple ID email used for notarization
APPLE_NOTARIZE_PASSWORD App-specific password for that Apple ID

Notes

  • CGO_ENABLED=0 is safe for the CLI: the CGo-gated WebKit detection code in internal/operatingsystem/webkit_linux.go is guarded by //go:build linux && cgo && !gtk4 && !android and is excluded when CGo is disabled. The resulting binary is fully functional.
  • The workflow_dispatch trigger accepts a tag input (must already exist) and a pre_release boolean — useful for test builds like v3.0.0-test.1.
  • Pre-release status is auto-detected from the tag: any tag containing a - (e.g. v3.0.0-beta.1) is marked as pre-release on GitHub.
  • If the release already exists when the job runs (e.g. a re-run), the job uploads binaries with --clobber instead of creating a new release.

Test plan

  • Push a test tag v3.0.0-test.1 to verify all 5 build targets compile
  • Confirm macOS binaries are signed: codesign -v wails3-darwin-*
  • Confirm notarization: spctl -a -v wails3-darwin-universal
  • Confirm binaries appear attached to the GitHub Release

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Improved the release automation to build and package binaries for Linux, Windows, and macOS in parallel.
    • Added macOS code signing and notarization steps before publishing artifacts.
    • Automatically creates or updates GitHub releases based on pushed version tags, with support for manual pre-release publishing.
    • Generates release notes and uploads the built distribution files to the release.

Builds wails3 CLI for linux/amd64, linux/arm64, darwin/amd64,
darwin/arm64, and a darwin universal binary on tag push matching
v3.*. macOS binaries are signed with Developer ID and notarized
via xcrun notarytool. All binaries are attached to the GitHub
Release created for the tag.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: multica-agent <github@multica.ai>
Copilot AI review requested due to automatic review settings May 3, 2026 12:54
@coderabbitai

coderabbitai Bot commented May 3, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 1e6512b4-f5e1-4bba-8a58-d1042d87cb2b

📥 Commits

Reviewing files that changed from the base of the PR and between 687f4d1 and d4ce50b.

📒 Files selected for processing (1)
  • .github/workflows/release-v3.yml

Walkthrough

A GitHub Actions workflow for Wails v3 is added that triggers on v3.* tag pushes or manual dispatch, builds Linux, Windows, and macOS binaries, signs and notarizes macOS outputs, and creates or updates a GitHub release.

Changes

Wails v3 Release Pipeline

Layer / File(s) Summary
Workflow triggers and platform builds
.github/workflows/release-v3.yml
The workflow adds v3.* tag and manual triggers, then defines Linux matrix builds and a Windows build that check out the requested tag, build static binaries, and upload artifacts.
macOS signing and notarization
.github/workflows/release-v3.yml
The macOS job builds amd64 and arm64 binaries, creates a universal binary, imports a signing certificate into a temporary keychain, signs the artifacts, notarizes them, and uploads the signed macOS outputs.
Release assembly and publication
.github/workflows/release-v3.yml
The release job resolves the tag and prerelease flag, downloads all artifacts into dist/, verifies the tag exists, and uses gh to create or update the GitHub release with the bundled binaries.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

  • wailsapp/wails#5270: Also changes GitHub workflow behavior around permissions needed for release-related automation.

Poem

🐰 I hopped through tags on v3 tonight,
Built Linux, Windows, Mac just right.
Signed and notarized with a cheerful grin,
Then sent the release out to begin.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise, specific, and accurately describes the new release workflow for signed v3 binaries.
Description check ✅ Passed The description is detailed and relevant, covering summary, secrets, notes, and test plan, but it omits the Fixes # reference and some checklist fields.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/engineer-linux/0908911e

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/release-v3.yml Fixed
Comment thread .github/workflows/release-v3.yml Fixed
Comment thread .github/workflows/release-v3.yml Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new GitHub Actions workflow for publishing signed wails3 v3 CLI releases. The workflow fits into the repository’s release automation by building cross-platform binaries, notarizing macOS artifacts, and publishing them to GitHub Releases.

Changes:

  • Adds a new tag-triggered/manual release-v3.yml workflow for v3 CLI release builds.
  • Builds Linux, Windows, and macOS binaries, including a universal macOS binary.
  • Signs and notarizes macOS artifacts, then creates or updates the GitHub Release and uploads all binaries.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/release-v3.yml
Comment thread .github/workflows/release-v3.yml
Comment thread .github/workflows/release-v3.yml Outdated
Comment thread .github/workflows/release-v3.yml
Comment thread .github/workflows/release-v3.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/release-v3.yml:
- Around line 24-26: Add an explicit minimal permissions block to each build job
to restrict GITHUB_TOKEN scope: for the jobs build-linux, build-windows, and
build-sign-macos add a permissions stanza under the job definition with at least
"contents: read" and "actions: write" (e.g., permissions: contents: read
actions: write) to allow checkout and artifact upload while limiting other token
privileges.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: a4701b0b-e8d0-468a-b002-cd2ef36e8a39

📥 Commits

Reviewing files that changed from the base of the PR and between 1c143ca and 687f4d1.

📒 Files selected for processing (1)
  • .github/workflows/release-v3.yml

Comment thread .github/workflows/release-v3.yml
@leaanthony

Copy link
Copy Markdown
Member Author

Self-review notes — two showstoppers before this workflow ships:

  1. workflow_dispatch builds the wrong commit — All three build jobs use bare actions/checkout@v4 with no ref: parameter. On a manual dispatch, the workflow builds from the current branch tip, not inputs.tag, then uploads those artifacts to the requested release. Fix:

    - uses: actions/checkout@v4
      with:
        ref: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref }}
  2. base64 --decode fails on macOS — macOS runners use BSD base64 which requires -D, not --decode. The certificate import step will error before signing starts. Fix: use base64 -d (works on both BSD and GNU).

Also worth fixing:

  • Each build job should have permissions: contents: read; only the release job needs contents: write. Currently write is inherited everywhere.
  • gh release create will create a tag at the wrong commit if inputs.tag doesn't already exist. Add a git fetch --tags && git rev-parse refs/tags/$TAG guard before the release step.

@taliesin-ai
taliesin-ai enabled auto-merge (squash) June 29, 2026 00:22
@taliesin-ai
taliesin-ai disabled auto-merge June 29, 2026 06:10
…tag guard, token perms)

- Pin build-job checkouts to inputs.tag on workflow_dispatch (github.ref on tag
  push) so binaries are built/signed from the requested tag, not the branch tip.
- Use BSD 'base64 -D' on macos-latest (--decode is GNU-only and would fail).
- Fail fast if the requested tag does not exist instead of letting
  'gh release create' create it at an arbitrary commit.
- Default GITHUB_TOKEN to 'contents: read'; release job keeps 'contents: write'.
@taliesin-ai

Copy link
Copy Markdown
Collaborator

Addressed the review feedback (thanks @copilot-pull-request-reviewer, CodeQL, @coderabbitai):

  • Wrong-commit on manual runs — all three build jobs now check out ref: ${{ inputs.tag || github.ref }}, so workflow_dispatch builds and signs the requested tag (tag-push still uses github.ref). Binaries can no longer be built from the branch tip and published under an unrelated tag.
  • macOS base64 — base64 --decode is GNU-only; macos-latest ships BSD base64, so the cert import now uses base64 -D.
  • Tag validation — before gh release create we now verify the tag exists via the refs API and fail fast otherwise, so a typo'd dispatch can't create a release at an arbitrary commit.
  • Token scope — added a top-level permissions: contents: read default; the release job keeps its contents: write. Resolves the CodeQL findings on the build jobs.

YAML validated. Re-enabling auto-merge.

@taliesin-ai
taliesin-ai enabled auto-merge (squash) June 29, 2026 06:19
@coderabbitai

coderabbitai Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

@taliesin-ai Thanks for the thorough follow-up — those fixes address the concerns I raised, especially the manual-dispatch ref handling and the macOS certificate decode portability.

🐇✨


If you found this review helpful, would you consider giving us a shout-out on X?

Thank you for using CodeRabbit!

@taliesin-ai taliesin-ai left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. Reviewed the release-workflow fixes: build jobs now check out inputs.tag || github.ref (correct commit on workflow_dispatch), macOS cert import uses BSD base64 -D, a tag-existence guard fails fast before gh release create, and GITHUB_TOKEN defaults to read-only with the release job scoped to write. YAML validated; all review threads resolved.

@taliesin-ai
taliesin-ai merged commit 312e8d0 into master Jun 29, 2026
17 checks passed
@taliesin-ai
taliesin-ai deleted the agent/engineer-linux/0908911e branch June 29, 2026 07:39
@github-project-automation github-project-automation Bot moved this from Todo to Done in Wails Release Train Jun 29, 2026
leaanthony added a commit that referenced this pull request Jul 26, 2026
release-v3.yml was added in #5318 and has never executed: every alpha has
shipped through nightly-release-v3.yml. Reviewing it before the beta turns up
four things that would each surface as a failed or misleading release.

The largest: none of the six Apple secrets it reads (APPLE_SIGNING_CERT,
APPLE_CERT_PASSWORD, APPLE_SIGNING_IDENTITY, APPLE_NOTARIZE_USER,
APPLE_NOTARIZE_PASSWORD, APPLE_TEAM_ID) exist on the repository. On the first
real run the macOS job would fail inside `security import` after three
platforms had already built, the release job would never run, and nothing
would be published.

Changes:

- New preflight job that fails in seconds rather than ten minutes in. It
  resolves the tag for both trigger paths, checks out that tag, and verifies
  v3/internal/version/version.txt matches it. version.txt is embedded, so a
  mismatch ships a binary that misreports its own version with no error at all.
- Preflight also reports exactly which Apple secrets are missing, and either
  stops or, with the new allow_unsigned_macos input, continues with the
  signing and notarization steps skipped. No silent downgrade either way.
- Publish SHA256SUMS alongside the binaries. Users currently have no way to
  verify a download.
- Attest build provenance for every binary. The npm package already ships
  provenance; the binaries lagging behind it is a gap users can see.
- New draft input, so the whole path can be rehearsed end to end and the
  resulting release deleted without ever publishing anything.

The build jobs now take their checkout ref from preflight's resolved tag, so
all three platforms provably build the same verified source.

Verified: actionlint clean; the version-guard, missing-secret detection and
checksum generation logic each exercised locally under bash -eo pipefail.
Not exercised in CI, because doing that means creating a tag and a release.

Claude-Session: https://claude.ai/code/session_01FigQqUQbNu9ngE4a2CSNm8

Co-authored-by: taliesin-ai <lea.anthony@gmail.com>
leaanthony added a commit that referenced this pull request Aug 11, 2026
* chore(v3): remove the desktop binary release pipeline

v3 releases are tag-only. The `wails3` CLI is installed with
`go install github.com/wailsapp/wails/v3/cmd/wails3@latest`, which is
what the installation docs tell users to do; no documentation, script,
or template resolves a release asset.

`release-v3.yml` (#5318) built six CLI binaries, SHA256SUMS, and a
provenance attestation on every v3 tag, and the nightly dispatched it
explicitly because a tag pushed with GITHUB_TOKEN emits no push event.
Because the nightly release script creates the GitHub release when it
pushes the tag, and releases on this repository are immutable, every
one of those dispatches then failed HTTP 422 uploading its first asset.
beta.2 through beta.6 published with zero assets for that reason.

Attaching binaries is deferred, not being fixed: the six APPLE_* signing
secrets were never configured, so the pipeline could only ever have
published unsigned macOS binaries. Removing it stops six platform builds
and a guaranteed failure on every nightly. Restore this commit when
binary releases are picked up again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore(changelog): point the entry at the right PR

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Lea Anthony <lea.anthony@gmail.com>
timlinde pushed a commit to Topborn/wails that referenced this pull request Aug 22, 2026
* chore(v3): remove the desktop binary release pipeline

v3 releases are tag-only. The `wails3` CLI is installed with
`go install github.com/wailsapp/wails/v3/cmd/wails3@latest`, which is
what the installation docs tell users to do; no documentation, script,
or template resolves a release asset.

`release-v3.yml` (wailsapp#5318) built six CLI binaries, SHA256SUMS, and a
provenance attestation on every v3 tag, and the nightly dispatched it
explicitly because a tag pushed with GITHUB_TOKEN emits no push event.
Because the nightly release script creates the GitHub release when it
pushes the tag, and releases on this repository are immutable, every
one of those dispatches then failed HTTP 422 uploading its first asset.
beta.2 through beta.6 published with zero assets for that reason.

Attaching binaries is deferred, not being fixed: the six APPLE_* signing
secrets were never configured, so the pipeline could only ever have
published unsigned macOS binaries. Removing it stops six platform builds
and a guaranteed failure on every nightly. Restore this commit when
binary releases are picked up again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore(changelog): point the entry at the right PR

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Lea Anthony <lea.anthony@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants