Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -364,7 +364,8 @@ jobs:
name: Assemble and attest release assets
if: ${{ always() && needs.build-release.result == 'success' && needs.build-windows.result == 'success' && needs.build-darwin.result == 'success' }}
needs: [build-release, build-windows, build-darwin]
runs-on: blacksmith-4vcpu-ubuntu-2404
# The updater rejects self-hosted attestations; keep final release signing on GitHub-hosted infrastructure.
runs-on: ubuntu-24.04
permissions:
attestations: write
contents: read
Expand All @@ -374,6 +375,12 @@ jobs:
GH_REPO: ${{ github.repository }}
VERSION: ${{ inputs.version }}
steps:
- name: Require GitHub-hosted attestation runner
shell: bash
run: |
set -euo pipefail
test "${RUNNER_ENVIRONMENT:-}" = "github-hosted"

- name: Checkout repository
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10
with:
Expand Down
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# Changelog

## 0.1.44-beta.17 - 2026-09-23

### Fixed

- Generate release provenance from GitHub-hosted assembly runners so in-app updates pass the self-hosted runner policy without weakening attestation verification.

### Tests

- Verify release checksums and provenance before the updater consumes release metadata.

## 0.1.44-beta.16 - 2026-09-23

### Added
Expand Down
Loading