fix(ci): migrate release signing to Azure Artifact Signing - #586
Conversation
|
Codex review: found issues before merge. Reviewed May 29, 2026, 10:35 AM ET / 14:35 UTC. Summary Reproducibility: not applicable. this is a release-signing workflow migration rather than a bug report. The relevant runtime evidence is the linked signing smoke runs and current-head CI status. Review metrics: 3 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Security Review findings
Review detailsBest possible solution: Land the migration after preserving or explicitly documenting the MSIX publisher upgrade path, confirming the release-signing OIDC environment, and letting current-head CI finish cleanly. Do we have a high-confidence way to reproduce the issue? Not applicable; this is a release-signing workflow migration rather than a bug report. The relevant runtime evidence is the linked signing smoke runs and current-head CI status. Is this the best way to solve the issue? No as-is; the OIDC/Artifact Signing direction is reasonable, but the MSIX publisher identity change needs explicit compatibility handling because v0.5.0 shipped MSIX assets under the old publisher. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against 32e6025d00c6. Label changesLabel changes:
Label justifications:
Evidence reviewedWhat I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
Summary
openclawaccount/profile in East USrelease-signingenvironmentValidation
ruby -e 'require "yaml"; YAML.load_file(".github/workflows/ci.yml")'git diff --checkopenclawsigning account/profile are active and the GitHub OIDC app hasArtifact Signing Certificate Profile Signeron the profile scopeLocal required gates blocked on this mac:
./build.ps1-> permission denied for direct ps1 execution in zshdotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore->dotnetnot installeddotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore->dotnetnot installed