Build App (Preview) / compute-version (pull_request) Successful in 5s
Secret Scan / scan (pull_request) Successful in 4s
Secret Scan / scan (push) Successful in 6s
Build App (Preview) / create-release (pull_request) Successful in 2s
Build App (Preview) / build-macos (pull_request) Successful in 3m19s
Build App (Preview) / test (pull_request) Successful in 4m59s
Build App (Preview) / build-linux (pull_request) Successful in 5m18s
Build App (Preview) / build-windows (pull_request) Failing after 5m32s
Build App (Preview) / prune-previews (pull_request) Skipped
Releases and PR previews now sign the app binary, the MSI, the NSIS installer and its uninstaller. "Verify signatures" fails the job on any unsigned or untimestamped .exe/.msi, so an unsigned installer can't ship quietly. - windows-signing-setup.ps1 fetches Microsoft.ArtifactSigning.Client 1.0.128 and a job-local .NET 10.0.12 runtime, each pinned by hash. Nothing is installed on the build VM. It also writes the dlib metadata and exports TAURI_CONFIG with bundle.windows.signCommand. - windows-sign.ps1 runs the installed signtool with /dlib, SHA-256 and the Microsoft timestamp server, with retries. Credentials come only from the AZURE_* environment. The metadata excludes every credential type except EnvironmentCredential, because InteractiveBrowserCredential would hang a job running as SYSTEM. - The signing files go in the workspace, not %TEMP%, because the uninstaller is signed from 32-bit makensis and WOW64 redirects SYSTEM's %TEMP%. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
22 lines
616 B
Plaintext
22 lines
616 B
Plaintext
node_modules/
|
|
app/dist/
|
|
app/src-tauri/target/
|
|
# Written by build.rs (tauri-build AppManifest); gen/schemas/acl-manifests.json is the
|
|
# tracked, reviewable form of the same information.
|
|
app/src-tauri/permissions/autogenerated/
|
|
Screenshot*.png
|
|
code-review.md
|
|
|
|
# Windows NTFS alternate-data-stream artifacts, created when files arrive
|
|
# through the WSL/host bind mount.
|
|
*:Zone.Identifier
|
|
|
|
# Local bug-report screenshots, same spirit as Screenshot*.png above.
|
|
screenshot_for_fix/
|
|
|
|
# Package files pulled in by ad-hoc verification runs.
|
|
*.deb
|
|
|
|
# Windows CI code signing (scripts/windows-signing-setup.ps1)
|
|
.code-signing/
|