Repository navigation
ci/release: remove macOS entirely (zero macOS) - #60
Merged
Merged
Conversation
added 2 commits
October 7, 2026 00:59
… Homebrew cask) Removes all macOS from CI, release, and distribution: - cross-platform-tests: drop macos-tests job (macos-15/26/intel legs) - benchmark-targets: drop macos/apple-silicon matrix entry - build-release-artifacts: drop build_macos job, MACOS_SIGNING_*/MACOS_NOTARY_* secrets, macOS artifact download/assembly, dmg args in cask generation - release path: Homebrew cask is now Linux-only (AppImage); deploy-homebrew-tap keeps publishing the Linux cask - deployment-ci: drop macos-packaging-smoke job; drop deleted macOS scripts from path triggers and bash -n; cask gate asserts Linux-only (no macos/.dmg/.app) - delete scripts/package-macos.sh, scripts/notarize-macos.sh, scripts/macos-cargo-config.sh - rewrite scripts/generate-homebrew-cask.sh to a Linux-only cask - delete docs/macos-release-signing.md; drop macOS from README/CONTRIBUTING install+packaging docs Windows and Linux distribution unchanged. App source cfg(target_os=macos) untouched (out of scope). Repo secrets not deleted; now-unused macOS secrets listed in PR body.
The 'Validate deployment workflow config keys' step asserted the literal microsoft/microsoft-store-apppublisher@v1.4, but deploy-microsoft-store.yml pins that action by commit SHA (@cc9910a8... # v1.4). Match the action reference plus its '# v1.4' version comment so the gate stays green. This step first runs on this PR because it is the first change to touch the deployment-ci trigger paths.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Removes macOS completely from CI, release, and distribution. Windows and Linux distribution are unchanged.
CI / tests
cross-platform-tests.yml: deleted themacos-testsjob (macos-15 / macos-26 / macos-15-intel legs).benchmark-targets.yml: removed themacos / apple-siliconmatrix entry.perf.yml/rust.yml: already Linux-only — no change needed.Release / distribution
build-release-artifacts.yml: deleted thebuild_macosjob; removed theMACOS_SIGNING_*/MACOS_NOTARY_*secret declarations fromworkflow_call; removed macOS artifact download + payload assembly inpublish_release_assets; the Homebrew cask is now generated from Linux AppImages only (no.dmgargs).scripts/generate-homebrew-cask.sh: rewritten to emit a Linux-only cask (AppImage). The Homebrew tap deploy (deploy-homebrew-tap.yml/release-manual-main.ymldeploy_homebrew_tap) is kept and now ships the Linux cask.scripts/package-macos.sh,scripts/notarize-macos.sh,scripts/macos-cargo-config.sh.docs/macos-release-signing.md: deleted.Gates kept green
deployment-ci.yml: deleted themacos-packaging-smokejob; removed the deleted macOS scripts from the path triggers and thebash -nvalidation; rewrote the synthetic-cask generation step and its assertions to a Linux-only cask (assertsos linux:/on_linux/ AppImage binary and now fails if anymacos/.dmg/GitComet.appcontent appears).Docs
README.md: "Available for Linux and Windows."; Homebrew section retitled "Homebrew (Linux)".CONTRIBUTING.md: dropped the macOS packaging commands and the macOS artifact bullet; cask bullet now says Linux-only.Out of scope (intentionally untouched)
cfg(target_os = "macos")incrates/**(per the task, CI/release/distribution/flake only). No tombstone comments added.flake.nixexists in this repo, so there was nothing to change there.Now-unused repo secrets (NOT deleted — just no longer referenced)
These macOS signing/notarization secrets are no longer read by any workflow and can be removed by a maintainer at their discretion:
MACOS_SIGNING_IDENTITYMACOS_SIGNING_CERT_BASE64MACOS_SIGNING_CERT_PASSWORDMACOS_NOTARY_KEY_IDMACOS_NOTARY_ISSUER_IDMACOS_NOTARY_API_KEY_P8Verification done locally
bash -nongenerate-homebrew-cask.shand the remaining release scripts.generate-homebrew-cask.shand replayed the fulldeployment-cicask gate (Linux-only assertions pass; the new no-macOS negative assert passes).build-release-artifacts.ymljob graph has no danglingneedsafter removingbuild_macos.Note (extra finding, not changed)
release-manual-main.ymlenforces dispatch frommainonly, but this repo's trunk isdev(nomainbranch exists). That predates this change and is unrelated to macOS, so it is left as-is.Pre-existing failing checks (inherited from
dev, NOT caused by this PR)This PR changes zero Rust/
Cargo.*files, so it cannot affect compilation, tests, or the dependency audit. The following checks fail on this PR and were confirmed failing ondevHEAD (2f5b3b7) by dispatchingrust.ymlandcross-platform-tests.ymlagainstdev:devHEAD (proof)Root causes (for maintainers; deliberately left unchanged by this macOS-scoped PR):
rust.yml's audit step builds--ignoreflags with"${IGNORES[@]/#/--ignore }", which fuses--ignore RUSTSEC-…into a single argument; a newercargo-auditrejects it (error: unexpected argument '--ignore RUSTSEC-2025-0052' found).dev.The only gate this PR actually fixed is
deployment-ci's "Validate deployment workflow config keys" step (commit6770e9c5): itsmicrosoft/microsoft-store-apppublisher@v1.4grep did not match the SHA-pinned@cc9910a8… # v1.4reference. That step was first exercised by this PR because this is the first change to touch thedeployment-citrigger paths. It now passes.