Skip to content

ci: the macOS zip publishes its checksum beside it - #105

Merged
sepehr-safari merged 1 commit into
mainfrom
the-macos-zip-publishes-its-checksum
Sep 25, 2026
Merged

sepehr-safari merged 1 commit into
mainfrom
the-macos-zip-publishes-its-checksum

Conversation

@sepehr-safari

Copy link
Copy Markdown
Contributor

Part of zig-nostr/plaza#361, which asks for the same change in both repos.

  • A new step writes Notary-vX.Y.Z-macos.zip.sha256 with shasum -a 256, the same <hash> <name> format the Linux .sha256 files use, and both publish branches upload it with the zip.
  • scripts/check-release-assets.sh expects it, so the draft stays hidden if it is missing. New self-test case: a macOS zip without its digest is refused, naming that file.

The installer keeps reading the digest from the release JSON for now. It always installs the latest release, so switching it before a release carries this file would break every macOS install. That switch, and deleting the JSON parsing, follow the next Notary release.

Each Linux tarball has always had a .sha256 next to it on the release; the macOS zip had none, which is why the macOS installer has to pick its digest out of the release JSON. The release now writes Notary-vX.Y.Z-macos.zip.sha256 in the same format and uploads it with the zip, and the publish check will not lift a draft without it.

Switching the installer to read it waits for a release that carries the file, since the installer always reads the latest release.
@sepehr-safari
sepehr-safari merged commit a3088ef into main Sep 25, 2026
6 checks passed
@sepehr-safari
sepehr-safari deleted the the-macos-zip-publishes-its-checksum branch September 25, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant