ci: assert the Developer ID identity imported - #8
Merged
Conversation
security find-identity exits 0 even when it finds "0 valid identities", so a p12 that imports but whose chain does not validate on the runner sailed past the import step and failed deep inside build-release.sh. Grep the identity out of the listing instead.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
security find-identity -v -p codesigningis informational: it exits 0 even when it prints0 valid identities found. A.p12that imports but whose chain does not validate on the runner would pass the import step and fail later, confusingly, insidebuild-release.sh.This matters here because the shipped p12 was produced by
SecItemExportrather than a Keychain Access GUI export, which is a different code path for whether the Developer ID intermediate is bundled.Now the step captures the listing, echoes it, and fails unless
APP_IDENTITYappears in it. Covers both "no identities" and "wrong identity".