Repository navigation
ci: add release-v3.yml workflow for signed v3 binary releases - #5318
Conversation
Builds wails3 CLI for linux/amd64, linux/arm64, darwin/amd64, darwin/arm64, and a darwin universal binary on tag push matching v3.*. macOS binaries are signed with Developer ID and notarized via xcrun notarytool. All binaries are attached to the GitHub Release created for the tag. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: multica-agent <github@multica.ai>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughA GitHub Actions workflow for Wails v3 is added that triggers on ChangesWails v3 Release Pipeline
Estimated code review effort🎯 4 (Complex) | ⏱️ ~45 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
Adds a new GitHub Actions workflow for publishing signed wails3 v3 CLI releases. The workflow fits into the repository’s release automation by building cross-platform binaries, notarizing macOS artifacts, and publishing them to GitHub Releases.
Changes:
- Adds a new tag-triggered/manual
release-v3.ymlworkflow for v3 CLI release builds. - Builds Linux, Windows, and macOS binaries, including a universal macOS binary.
- Signs and notarizes macOS artifacts, then creates or updates the GitHub Release and uploads all binaries.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/release-v3.yml:
- Around line 24-26: Add an explicit minimal permissions block to each build job
to restrict GITHUB_TOKEN scope: for the jobs build-linux, build-windows, and
build-sign-macos add a permissions stanza under the job definition with at least
"contents: read" and "actions: write" (e.g., permissions: contents: read
actions: write) to allow checkout and artifact upload while limiting other token
privileges.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: a4701b0b-e8d0-468a-b002-cd2ef36e8a39
📒 Files selected for processing (1)
.github/workflows/release-v3.yml
|
Self-review notes — two showstoppers before this workflow ships:
Also worth fixing:
|
…tag guard, token perms) - Pin build-job checkouts to inputs.tag on workflow_dispatch (github.ref on tag push) so binaries are built/signed from the requested tag, not the branch tip. - Use BSD 'base64 -D' on macos-latest (--decode is GNU-only and would fail). - Fail fast if the requested tag does not exist instead of letting 'gh release create' create it at an arbitrary commit. - Default GITHUB_TOKEN to 'contents: read'; release job keeps 'contents: write'.
|
Addressed the review feedback (thanks @copilot-pull-request-reviewer, CodeQL, @coderabbitai):
YAML validated. Re-enabling auto-merge. |
|
Tip For best results, initiate chat on the files or code changes.
🐇✨ If you found this review helpful, would you consider giving us a shout-out on X? Thank you for using CodeRabbit! |
taliesin-ai
left a comment
There was a problem hiding this comment.
Approving. Reviewed the release-workflow fixes: build jobs now check out inputs.tag || github.ref (correct commit on workflow_dispatch), macOS cert import uses BSD base64 -D, a tag-existence guard fails fast before gh release create, and GITHUB_TOKEN defaults to read-only with the release job scoped to write. YAML validated; all review threads resolved.
release-v3.yml was added in #5318 and has never executed: every alpha has shipped through nightly-release-v3.yml. Reviewing it before the beta turns up four things that would each surface as a failed or misleading release. The largest: none of the six Apple secrets it reads (APPLE_SIGNING_CERT, APPLE_CERT_PASSWORD, APPLE_SIGNING_IDENTITY, APPLE_NOTARIZE_USER, APPLE_NOTARIZE_PASSWORD, APPLE_TEAM_ID) exist on the repository. On the first real run the macOS job would fail inside `security import` after three platforms had already built, the release job would never run, and nothing would be published. Changes: - New preflight job that fails in seconds rather than ten minutes in. It resolves the tag for both trigger paths, checks out that tag, and verifies v3/internal/version/version.txt matches it. version.txt is embedded, so a mismatch ships a binary that misreports its own version with no error at all. - Preflight also reports exactly which Apple secrets are missing, and either stops or, with the new allow_unsigned_macos input, continues with the signing and notarization steps skipped. No silent downgrade either way. - Publish SHA256SUMS alongside the binaries. Users currently have no way to verify a download. - Attest build provenance for every binary. The npm package already ships provenance; the binaries lagging behind it is a gap users can see. - New draft input, so the whole path can be rehearsed end to end and the resulting release deleted without ever publishing anything. The build jobs now take their checkout ref from preflight's resolved tag, so all three platforms provably build the same verified source. Verified: actionlint clean; the version-guard, missing-secret detection and checksum generation logic each exercised locally under bash -eo pipefail. Not exercised in CI, because doing that means creating a tag and a release. Claude-Session: https://claude.ai/code/session_01FigQqUQbNu9ngE4a2CSNm8 Co-authored-by: taliesin-ai <lea.anthony@gmail.com>
* chore(v3): remove the desktop binary release pipeline v3 releases are tag-only. The `wails3` CLI is installed with `go install github.com/wailsapp/wails/v3/cmd/wails3@latest`, which is what the installation docs tell users to do; no documentation, script, or template resolves a release asset. `release-v3.yml` (#5318) built six CLI binaries, SHA256SUMS, and a provenance attestation on every v3 tag, and the nightly dispatched it explicitly because a tag pushed with GITHUB_TOKEN emits no push event. Because the nightly release script creates the GitHub release when it pushes the tag, and releases on this repository are immutable, every one of those dispatches then failed HTTP 422 uploading its first asset. beta.2 through beta.6 published with zero assets for that reason. Attaching binaries is deferred, not being fixed: the six APPLE_* signing secrets were never configured, so the pipeline could only ever have published unsigned macOS binaries. Removing it stops six platform builds and a guaranteed failure on every nightly. Restore this commit when binary releases are picked up again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(changelog): point the entry at the right PR Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Lea Anthony <lea.anthony@gmail.com>
* chore(v3): remove the desktop binary release pipeline v3 releases are tag-only. The `wails3` CLI is installed with `go install github.com/wailsapp/wails/v3/cmd/wails3@latest`, which is what the installation docs tell users to do; no documentation, script, or template resolves a release asset. `release-v3.yml` (wailsapp#5318) built six CLI binaries, SHA256SUMS, and a provenance attestation on every v3 tag, and the nightly dispatched it explicitly because a tag pushed with GITHUB_TOKEN emits no push event. Because the nightly release script creates the GitHub release when it pushes the tag, and releases on this repository are immutable, every one of those dispatches then failed HTTP 422 uploading its first asset. beta.2 through beta.6 published with zero assets for that reason. Attaching binaries is deferred, not being fixed: the six APPLE_* signing secrets were never configured, so the pipeline could only ever have published unsigned macOS binaries. Removing it stops six platform builds and a guaranteed failure on every nightly. Restore this commit when binary releases are picked up again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(changelog): point the entry at the right PR Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Lea Anthony <lea.anthony@gmail.com>
Summary
Adds
.github/workflows/release-v3.yml— a GitHub Actions workflow that:v3.*(and supportsworkflow_dispatchfor dry-run / manual test builds)wails3CLI binary for all 5 required targets usingCGO_ENABLED=0for portable, statically-linked binaries:linux/amd64—ubuntu-latestrunnerlinux/arm64—ubuntu-24.04-arm(native ARM64 runner)darwin/amd64—macos-latestrunnerdarwin/arm64—macos-latestrunner (GOARCH=arm64)darwin universal—lipo -createmerge of the two darwin binarieswindows/amd64—windows-latestrunnercodesign --options=runtime --timestampxcrun notarytool submit --waitRequired GitHub Actions secrets
Configure these in Settings → Secrets and variables → Actions before pushing a
v3.*tag:APPLE_SIGNING_CERTAPPLE_CERT_PASSWORDAPPLE_SIGNING_IDENTITYDeveloper ID Application: Wails (XXXXXXXXXX)APPLE_TEAM_IDAPPLE_NOTARIZE_USERAPPLE_NOTARIZE_PASSWORDNotes
CGO_ENABLED=0is safe for the CLI: the CGo-gated WebKit detection code ininternal/operatingsystem/webkit_linux.gois guarded by//go:build linux && cgo && !gtk4 && !androidand is excluded when CGo is disabled. The resulting binary is fully functional.workflow_dispatchtrigger accepts ataginput (must already exist) and apre_releaseboolean — useful for test builds likev3.0.0-test.1.-(e.g.v3.0.0-beta.1) is marked as pre-release on GitHub.--clobberinstead of creating a new release.Test plan
v3.0.0-test.1to verify all 5 build targets compilecodesign -v wails3-darwin-*spctl -a -v wails3-darwin-universal🤖 Generated with Claude Code
Summary by CodeRabbit