Skip to content

signing setup: write the builder.json profile only when its secrets were uploaded - #39

Merged
Interlap01 merged 1 commit into
mainfrom
signing/profile-only-with-secrets
Oct 7, 2026
Merged

Interlap01 merged 1 commit into
mainfrom
signing/profile-only-with-secrets

Conversation

@Interlap01

Copy link
Copy Markdown
Collaborator

A profile in builder.json says the signing set is ready to build with. When the secret upload failed (for example an agent platform's GitHub token, which cannot write repository secrets), signing setup wrote the profile anyway. Builds then failed late on missing secrets, and anyone reading builder.json (an agent that cannot list secrets included) was told signing was ready.

  • signing.Setup writes the profile only when SecretsUploaded; the new SetupResult.ProfileWritten reports it.
  • Both CLI modes (App Store Connect and manual) print Not updated: builder.json instead of the profile line on a failed upload. Everything else (files, printed values, exit code) is unchanged.
  • The two failed-upload tests now assert the profile is absent and the skip is reported.

go test ./cmd/builder/ ./internal/signing/ passes.

…ere uploaded

A profile in builder.json says the signing set is ready to build with. When
the upload failed (a token that cannot write repository secrets, such as an
agent platform's), writing it anyway made builds fail late on missing
secrets and misled anyone reading builder.json, agents that cannot list
secrets included. Both setup modes now skip the profile and say so; the
library reports it in SetupResult.ProfileWritten.
@Interlap01
Interlap01 merged commit e42a7aa into main Oct 7, 2026
8 checks passed
Interlap01 added a commit that referenced this pull request Oct 7, 2026
… no profile (#40)

Follow-up to #39: the help text and the README still said the build profile
is written regardless of the upload.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant