Skip to content

Publish signed release manifests with packslip - #16

Closed
sevein wants to merge 1 commit into
omlahore:mainfrom
sevein:dev/packslip
Closed

sevein wants to merge 1 commit into
omlahore:mainfrom
sevein:dev/packslip

Conversation

@sevein

@sevein sevein commented Oct 6, 2026 •

Copy link
Copy Markdown

Release archives currently leave installers to infer platforms and executable paths. Packslip is a promising fit here: its signed metadata lets tools such as mise select and verify the download directly.

The pinned action links existing build provenance and attaches the manifest before publication. The README adds packslip and mise examples and makes manual downloads stop on verification failure.

Summary by CodeRabbit

  • New Features
    • Added Homebrew, Packslip, and mise installation options, alongside instructions for manually downloading and installing archives.
    • Added guidance for verifying downloads using build provenance, signed manifests, and SHA-256 checksums.
    • Releases now include a signed manifest for supported versions; Packslip and mise require releases with this manifest.
  • Improvements
    • Release notes are included in draft releases before publication.

Release archives currently leave installers to infer platforms and
executable paths. Packslip is a promising fit here: its signed metadata
lets tools such as mise select and verify the download directly.

The pinned action links existing build provenance and attaches the
manifest before publication. The README adds packslip and mise examples
and makes manual downloads stop on verification failure.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: feba5e11-2576-4040-9adb-e4c9650584a7
📥 Commits

Reviewing files that changed from the base of the PR and between 28f6399 and c994bbe.

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • README.md

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The release workflow now creates a draft, signs and uploads a release manifest, links attestation, and publishes the release. The README adds installation options, manual archive steps, and download verification commands.

Changes

Release distribution

Layer / File(s) Summary
Draft, sign, and publish release
.github/workflows/release.yml
The workflow limits global permissions, creates the release as a draft, and runs a dependent Ubuntu Packslip job to sign and upload a manifest and link attestation. It then publishes the draft.
Installation and download verification
README.md
The README adds Homebrew, Packslip, mise, and manual installation instructions. It documents checksum and quarantine steps, and adds GitHub build-provenance and Packslip manifest verification commands.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseJob as release job
  participant GitHubRelease as GitHub release
  participant PackslipJob as packslip job
  participant PackslipAction as Packslip action
  ReleaseJob->>GitHubRelease: Create draft with changelog notes and assets
  PackslipJob->>PackslipAction: Run for Darwin ARM64 archive
  PackslipAction->>GitHubRelease: Upload signed manifest and link attestation
  PackslipJob->>GitHubRelease: Publish draft
Loading

Suggested reviewers: omlahore

Merge Risk: ⚪ Minimal · up to c994b

The release workflow produces a manifest and archive that the documented verification command selects correctly; no actionable merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: publishing signed release manifests with Packslip.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sevein sevein closed this Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant