Skip to content

release: enable the Portal download for v0.1.1 - #143

Merged
FelineStateMachine merged 1 commit into
mainfrom
release/enable-portal-download
Jul 26, 2026
Merged

release: enable the Portal download for v0.1.1#143
FelineStateMachine merged 1 commit into
mainfrom
release/enable-portal-download

Conversation

@FelineStateMachine

Copy link
Copy Markdown
Owner

Flips website/portal-release.json to the published v0.1.1 build — this is what enables goq.sh's download button.

Verified before flipping, not after

The runbook wants the artifact checked as a stranger receives it:

  • SHA-256 recomputed against the published checksum: d354f4df…1436afb2
  • gh attestation verify --repo FelineStateMachine/goq
  • App inside the mounted DMG: Signature=adhoc, Identifier=sh.goq.portal
  • spctl --assessrejected, which is the correct and documented result for an ad-hoc build that is deliberately not notarized

Also retires signed release channel pending from the Sigil note — v0.1.1 published it and install-sigil pins that tag.

verify-portal-release.py website and website_static_gate=ok.

Flips website/portal-release.json to the published v0.1.1 build, which is what
takes goq.sh's download button out of its disabled state.

The runbook asks for the artifact to be verified before this flip rather than
after, so the bytes were checked as a stranger receives them: SHA-256 recomputed
against the published checksum, `gh attestation verify` clean, and the app
inside the mounted DMG reports Signature=adhoc with identifier sh.goq.portal.
`spctl --assess` rejects it, which is the documented and expected result for an
ad-hoc build that is deliberately not notarized.

The Sigil install note also stops calling the signed channel pending, since
v0.1.1 published it and install-sigil now pins that tag.
@FelineStateMachine
FelineStateMachine merged commit 7ad5cad into main Jul 26, 2026
6 checks passed
@FelineStateMachine
FelineStateMachine deleted the release/enable-portal-download branch July 26, 2026 02:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant