diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 6881519..d60c3ad 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -364,7 +364,8 @@ jobs: name: Assemble and attest release assets if: ${{ always() && needs.build-release.result == 'success' && needs.build-windows.result == 'success' && needs.build-darwin.result == 'success' }} needs: [build-release, build-windows, build-darwin] - runs-on: blacksmith-4vcpu-ubuntu-2404 + # The updater rejects self-hosted attestations; keep final release signing on GitHub-hosted infrastructure. + runs-on: ubuntu-24.04 permissions: attestations: write contents: read @@ -374,6 +375,12 @@ jobs: GH_REPO: ${{ github.repository }} VERSION: ${{ inputs.version }} steps: + - name: Require GitHub-hosted attestation runner + shell: bash + run: | + set -euo pipefail + test "${RUNNER_ENVIRONMENT:-}" = "github-hosted" + - name: Checkout repository uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 with: diff --git a/CHANGELOG.md b/CHANGELOG.md index 6965d40..900cd6a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,15 @@ # Changelog +## 0.1.44-beta.17 - 2026-09-23 + +### Fixed + +- Generate release provenance from GitHub-hosted assembly runners so in-app updates pass the self-hosted runner policy without weakening attestation verification. + +### Tests + +- Verify release checksums and provenance before the updater consumes release metadata. + ## 0.1.44-beta.16 - 2026-09-23 ### Added