mirror of
https://github.com/openai/codex.git
synced 2026-09-29 16:57:06 +08:00
Sign bundled macOS helper binaries (#35264)
## Why The macOS release workflow fetched `rg` and zsh while assembling package archives, after the signing stage. This left the bundled helper executables outside the workflow's signing and notarization checks. ## What changed - Fetch, sign, notarize, and upload the pinned macOS `rg` and zsh binaries with the other release artifacts. - Build package archives from those signed helpers via `--rg-bin` and the new `--zsh-bin` override. - Verify the helpers' architecture, signatures, and absence of entitlements in the final package. ## Testing - Cover the prebuilt zsh override and verify that package assembly preserves the supplied helper binaries. GitOrigin-RevId: a3865c04fa2f0f4df32e627ee7202bc87bdc3241
This commit is contained in:
committed by
copyberry
parent
0d2a0aa76b
commit
a453588416
@@ -78,6 +78,6 @@ The patched zsh fork used by `shell_zsh_fork` is fetched from the DotSlash
|
||||
manifest at `scripts/codex_package/codex-zsh` when the selected target has a
|
||||
matching prebuilt artifact. Downloaded archives are cached under
|
||||
`$TMPDIR/codex-package/<target>-zsh` and installed at
|
||||
`codex-resources/zsh/bin/zsh`. Pass `--zsh-manifest` to use a different
|
||||
DotSlash manifest, such as the manifest published with a standalone zsh
|
||||
artifact release.
|
||||
`codex-resources/zsh/bin/zsh`. Pass `--zsh-bin` to package a prebuilt, signed
|
||||
executable, or `--zsh-manifest` to use a different DotSlash manifest, such as
|
||||
the manifest published with a standalone zsh artifact release.
|
||||
|
||||
Reference in New Issue
Block a user