Skip to content

Prepare repository for public release - #11

Merged
bethvourc merged 3 commits into
mainfrom
chore/open-source-readiness
Sep 22, 2026
Merged

bethvourc merged 3 commits into
mainfrom
chore/open-source-readiness

Conversation

@bethvourc

@bethvourc bethvourc commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Cleans up the repo for public use and forking. I audited the full history on every branch (98 commits) first. No real secret was ever committed, so no history rewrite or key rotation is needed.

Safety

  • .gitignore hardening. The real mcp.json wasn't ignored, and it can hold Slack/Notion tokens. It's ignored now, along with signing material (*.p12, *.p8, *.pem, provisioning profiles), service-account keys, local SQLite state, DMGs, and editor settings.
  • Apple Team ID is no longer committed. DEVELOPMENT_TEAM moved from project.yml into apps/macos/Config/Signing.xcconfig, which optionally includes a git-ignored Signing.local.xcconfig. Forks build without inheriting someone else's team. CI and release are unaffected because both already build with CODE_SIGNING_ALLOWED=NO and re-sign with Developer ID.
  • Replaced a real name in the Home screen UI-test fixture and in the README examples.
  • CI now runs with a read-only GITHUB_TOKEN and cancels superseded runs.
  • CI fix: SwiftFormat is pinned to 0.61.1, verified by SHA-256. Homebrew had moved to 0.63.0, which adds default-on wrapping rules that flagged 30 untouched files and failed every PR.

Docs

  • Rewrote the README: features, architecture, quick start from a fresh clone, configuration table, safety tiers, building the macOS app, and development. I checked each claim against the code, and every ./iris command in it parses.
  • Reorganized .env.example into required/optional sections. Keys and defaults are unchanged.
  • Removed the internal readiness-review.md checklist and references to the private implementation plan.

Community

  • Added LICENSE (MIT, as pyproject.toml already declared), CONTRIBUTING.md, SECURITY.md, issue and PR templates, and Dependabot for GitHub Actions and uv.
  • Added project URLs, keywords, and classifiers to pyproject.toml.

Note: this branch is based on desktop-macos, so it also carries that branch's 7 commits that aren't on main yet (agent loop, resilience drills, runbook, release workflow fix).

Testing

  • uv run pytest -q: 278 passed
  • uv run ruff check src tests: clean
  • swiftlint --strict and swiftformat --lint .: clean
  • xcodebuild test -scheme Iris CODE_SIGNING_ALLOWED=NO: 158 passed
  • xcodegen generate is byte-identical before the spec change. DEVELOPMENT_TEAM resolves to the local team when Signing.local.xcconfig exists and is empty when it doesn't.

Follow-up for forks

To sign locally, create apps/macos/Config/Signing.local.xcconfig containing DEVELOPMENT_TEAM = <your team>.

🤖 Generated with Claude Code

bethvourc and others added 3 commits August 13, 2026 21:14
Two defects in the release pipeline, both found while dry-running it:

1. An untagged `workflow_dispatch` run — the dry run the docs recommend —
   always failed at the final step. action-gh-release derives its tag from
   `github.ref`, which is a branch on a manual dispatch, so it errored with
   "requires a tag" after the build, signing, and notarization had all
   succeeded. Publishing is now gated on a tag ref, and untagged runs upload
   the DMG as a workflow artifact instead, so a dry run leaves no draft
   releases behind.

2. The `.sha256` file recorded the absolute runner path, so `shasum -c`
   failed for anyone who downloaded it. It now hashes the bare filename.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Safety
- Ignore mcp.json (real MCP config can hold tokens), signing material
  (*.p12, *.p8, *.pem, provisioning profiles), service-account keys,
  local SQLite state, DMGs, and editor settings.
- Move the Apple DEVELOPMENT_TEAM out of the committed project into
  Config/Signing.xcconfig, which optionally includes a git-ignored
  Signing.local.xcconfig. Forks no longer inherit someone else's team.
- Replace a real name in the Home screen UI-test fixture.
- CI now runs with a read-only token and cancels superseded runs.

Docs
- Rewrite README: features, architecture, quick start from a fresh clone,
  configuration table, safety model, macOS app build, development.
- Reorganize .env.example into required/optional sections (keys and
  defaults unchanged).
- Remove the internal readiness-review checklist and references to the
  private implementation plan.

Community
- Add LICENSE (MIT, as already declared in pyproject.toml), CONTRIBUTING,
  SECURITY, issue and PR templates, and Dependabot for Actions and uv.
- Add project URLs, keywords, and classifiers to pyproject.toml.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Homebrew now installs SwiftFormat 0.63.0, which adds default-on rules
(wrapIfStatementBodies, wrapIfExpressionBodies) and flags 30 untouched
files, so every PR failed the macOS lint step. Disabling the rules in
.swiftformat isn't an option because older versions reject unknown rule
names, which would break local linting.

Install 0.61.1 from the GitHub release instead, verified by SHA-256.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@bethvourc
bethvourc merged commit cf5e2c4 into main Sep 22, 2026
3 checks passed
@bethvourc
bethvourc deleted the chore/open-source-readiness branch September 22, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant