Repository navigation
Prepare repository for public release - #11
Merged
Merged
Conversation
Two defects in the release pipeline, both found while dry-running it: 1. An untagged `workflow_dispatch` run — the dry run the docs recommend — always failed at the final step. action-gh-release derives its tag from `github.ref`, which is a branch on a manual dispatch, so it errored with "requires a tag" after the build, signing, and notarization had all succeeded. Publishing is now gated on a tag ref, and untagged runs upload the DMG as a workflow artifact instead, so a dry run leaves no draft releases behind. 2. The `.sha256` file recorded the absolute runner path, so `shasum -c` failed for anyone who downloaded it. It now hashes the bare filename. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Safety - Ignore mcp.json (real MCP config can hold tokens), signing material (*.p12, *.p8, *.pem, provisioning profiles), service-account keys, local SQLite state, DMGs, and editor settings. - Move the Apple DEVELOPMENT_TEAM out of the committed project into Config/Signing.xcconfig, which optionally includes a git-ignored Signing.local.xcconfig. Forks no longer inherit someone else's team. - Replace a real name in the Home screen UI-test fixture. - CI now runs with a read-only token and cancels superseded runs. Docs - Rewrite README: features, architecture, quick start from a fresh clone, configuration table, safety model, macOS app build, development. - Reorganize .env.example into required/optional sections (keys and defaults unchanged). - Remove the internal readiness-review checklist and references to the private implementation plan. Community - Add LICENSE (MIT, as already declared in pyproject.toml), CONTRIBUTING, SECURITY, issue and PR templates, and Dependabot for Actions and uv. - Add project URLs, keywords, and classifiers to pyproject.toml. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Homebrew now installs SwiftFormat 0.63.0, which adds default-on rules (wrapIfStatementBodies, wrapIfExpressionBodies) and flags 30 untouched files, so every PR failed the macOS lint step. Disabling the rules in .swiftformat isn't an option because older versions reject unknown rule names, which would break local linting. Install 0.61.1 from the GitHub release instead, verified by SHA-256. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Cleans up the repo for public use and forking. I audited the full history on every branch (98 commits) first. No real secret was ever committed, so no history rewrite or key rotation is needed.
Safety
.gitignorehardening. The realmcp.jsonwasn't ignored, and it can hold Slack/Notion tokens. It's ignored now, along with signing material (*.p12,*.p8,*.pem, provisioning profiles), service-account keys, local SQLite state, DMGs, and editor settings.DEVELOPMENT_TEAMmoved fromproject.ymlintoapps/macos/Config/Signing.xcconfig, which optionally includes a git-ignoredSigning.local.xcconfig. Forks build without inheriting someone else's team. CI and release are unaffected because both already build withCODE_SIGNING_ALLOWED=NOand re-sign with Developer ID.GITHUB_TOKENand cancels superseded runs.Docs
./iriscommand in it parses..env.exampleinto required/optional sections. Keys and defaults are unchanged.readiness-review.mdchecklist and references to the private implementation plan.Community
LICENSE(MIT, aspyproject.tomlalready declared),CONTRIBUTING.md,SECURITY.md, issue and PR templates, and Dependabot for GitHub Actions and uv.pyproject.toml.Testing
uv run pytest -q: 278 passeduv run ruff check src tests: cleanswiftlint --strictandswiftformat --lint .: cleanxcodebuild test -scheme Iris CODE_SIGNING_ALLOWED=NO: 158 passedxcodegen generateis byte-identical before the spec change.DEVELOPMENT_TEAMresolves to the local team whenSigning.local.xcconfigexists and is empty when it doesn't.Follow-up for forks
To sign locally, create
apps/macos/Config/Signing.local.xcconfigcontainingDEVELOPMENT_TEAM = <your team>.🤖 Generated with Claude Code