Skip to content

[blocker]: Hosted release workflow and signing custody #5

@gchahal1982

Description

@gchahal1982

Source PRD rows: docs/prds/agent-studio-open-prd.md:1135, docs/prds/agent-studio-open-prd.md:1187, docs/prds/open-studio-platform-prd.md:1698.

Current verified state as of 2026-05-19:

  • macOS notarization, signed SHA256SUMS, updater manifest, and public release assets exist for the current release.
  • Hosted release workflow has not produced the full cross-OS signed GA artifact set.
  • Hosted release/HSM custody variables and secrets are not configured in the checked repos.

Completion criteria:

  • Hosted release secrets/variables are configured through controlled custody.
  • Release workflow runs from a tag and produces signed macOS, Windows, and Linux artifacts.
  • Release assets publish to GitHub Releases and Cloudflare R2 as expected.

Verification commands:

  • pnpm --dir opensource/open-studio-platform run verify:signing-custody
  • pnpm --dir opensource/open-studio-platform run verify:release-blockers -- --probe-uptime

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockerExternal or release blocker with dated next actionciGitHub Actions, required checks, runner, or green-history validationreleaseRelease packaging, signing, registries, or launch readinesssigningApple, Windows, notarization, certificate, or signed artifact readiness

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions