rowboat/apps/x
Ramnique Singh 95618a364f
feat(x): sign Windows builds with Azure Trusted Signing in CI (#783)
* feat(x): sign Windows builds with Azure Trusted Signing in CI

Wire windowsSign (packager + Squirrel maker) through Azure Trusted
Signing's signtool dlib. Signing activates only when the CI env vars
are present; local and mac/linux builds are unaffected. The Windows
job stages the dlib, metadata.json, and a modern SDK signtool under
C:\azsign (space-free paths — @electron/windows-sign splits
signWithParams on spaces).

Requires repo secrets: AZURE_TENANT_ID, AZURE_CLIENT_ID,
AZURE_CLIENT_SECRET, AZURE_ENDPOINT, AZURE_CODE_SIGNING_NAME,
AZURE_CERT_PROFILE_NAME.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ci): use renamed Microsoft.ArtifactSigning.Client NuGet package

Microsoft renamed Trusted Signing to Artifact Signing and delisted the
old Microsoft.Trusted.Signing.Client package, which broke the setup
step. The dlib inside kept its Azure.CodeSigning.Dlib.dll filename;
locate it by search instead of a hardcoded path so future package
reshuffles fail loudly rather than at a stale path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ci): don't run bare signtool in the signing setup step

signtool with no arguments prints usage and exits 1, and the Actions
pwsh wrapper propagates the last native exit code as the step result,
failing the job after an otherwise successful setup. Log the signtool
version from file metadata instead.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(x): stage only the current platform's node-pty prebuilds

Every build shipped all platforms' prebuilt binaries. Windows code
signing walks every .node file in the app and signtool hard-fails on
the Mach-O darwin pty.node ("file format cannot be signed"). Filtering
to the host platform fixes signing and drops dead weight from all
installers. The Linux CI-compiled prebuild and the node-gyp self-heal
path both still stage correctly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 14:12:39 +05:30
..
.pnpm-store/v11 add talking mascot 2026-07-02 22:20:11 +05:30
apps feat(x): sign Windows builds with Azure Trusted Signing in CI (#783) 2026-07-23 14:12:39 +05:30
docs feat(apps): M3 UI — catalog, D18 install dialog, publish dialog, detail actions 2026-07-06 15:34:54 +05:30
packages Merge branch 'main' into feat/configurable-model-call-limit 2026-07-22 10:53:12 +05:30
.gitignore feat(x): reference-based model requests + wire-form composer 2026-07-02 14:20:44 +05:30
ANALYTICS.md Log background agent failure reasons 2026-07-22 10:48:36 +05:30
CODE_MODE_ENGINES_PLAN.md Code mode: make packaged builds work via managed engine provisioning (#625) 2026-06-17 21:53:15 +05:30
demo.gif add gif 2026-07-10 10:04:37 +05:30
eslint.config.mts ignore renderer eslint 2026-01-16 12:05:33 +05:30
GRANOLA_PARITY.md feat(x): resident app — launch at login + menu bar tray (Granola parity phase 1) 2026-07-13 21:02:20 +05:30
LIVE_NOTE.md docs(x): design docs and prompt catalogs follow the runtime/ move 2026-07-10 16:30:26 +05:30
MINI_APPS_PLAN.md feat(mini-apps): copilot builder — build-mini-app skill + install/data tools 2026-07-01 01:25:45 +05:30
package.json ci(x): typecheck test files — the gap vitest and the build tsconfigs both miss 2026-07-10 16:30:26 +05:30
pnpm-lock.yaml feat(x): client auto-update with restart card and inline release notes (#744) 2026-07-16 17:59:03 +05:30
pnpm-workspace.yaml build(x): graft vscode-jsonrpc onto langium via packageExtensions 2026-07-07 02:45:09 +05:30
tsconfig.base.json bootstrap new electron app 2026-01-16 12:05:33 +05:30
VIDEO_MODE.md docs(x): fix pointers the reorg docs pass got wrong or missed 2026-07-10 17:57:03 +05:30