fix(release): require the macOS publish destination before building

This commit is contained in:
ethernet
2026-09-06 21:30:06 -04:00
parent da236308fd
commit baad1579d4
2 changed files with 3 additions and 1 deletions

View File

@@ -665,6 +665,8 @@ jobs:
[ -z "$APPLE_API_KEY_P8" ] && missing+=(APPLE_API_KEY_P8)
[ -z "$APPLE_API_KEY_ID" ] && missing+=(APPLE_API_KEY_ID)
[ -z "$APPLE_API_ISSUER" ] && missing+=(APPLE_API_ISSUER)
[ -z "$CLOUDFLARE_R2_PUBLIC_URL" ] && missing+=(CLOUDFLARE_R2_PUBLIC_URL)
[ -z "$CLOUDFLARE_R2_BUCKET" ] && missing+=(CLOUDFLARE_R2_BUCKET)
if [ ${#missing[@]} -gt 0 ]; then
echo "::error::upload_release=true but required signing/notarization credentials are not set in the release-signing environment: ${missing[*]} — refusing to produce an unsigned publishable build"
exit 1

View File

@@ -22,7 +22,7 @@
// releases/win32/<channel>/*.msixbundle (produced by the
// publish-win32-updater job)
// releases/darwin/<channel>/<channel>-mac.yml electron-updater feed
// releases/darwin/<channel>/*.{dmg,zip,blockmap}
// dmg/zip/blockmap artifacts stay in releases/tag/<tag>/.
// where <channel> is stable | canary (from the tag: -canary. → canary).
// The publish-win32-updater job merges the win32 legs' staging into the
// win32 feed; r2 finalize publishes the validated Darwin channel feed.