Skip to content

Add protected GitHub release automation - #2

Merged
kwatson merged 1 commit into
mainfrom
codex/release-automation
Aug 13, 2026
Merged

Add protected GitHub release automation#2
kwatson merged 1 commit into
mainfrom
codex/release-automation

Conversation

@kwatson

@kwatson kwatson commented Aug 13, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a strict CHANGELOG.md-driven vX.Y.Z release contract
  • build the OpenClaw plugin, Thunderbird XPI, and Mozilla reviewer source once
  • qualify the exact candidate bytes across Linux and Windows, with native Apple Silicon filesystem/security coverage
  • reproduce the XPI from the submitted reviewer source and scan unpacked release contents
  • require approval through the protected release environment before creating the GitHub release

Publication boundary

This creates GitHub releases only. It does not publish to ClawHub or Thunderbird Add-ons; the first marketplace submissions remain manual and must use the attached exact bytes.

Verification

  • mise exec -- npm test (320/320)
  • mise exec -- npm run typecheck
  • mise exec -- npm run pack:release
  • source archive clean rebuild/content comparison
  • checksum-pinned Gitleaks scan of unpacked artifacts

Signed-off-by: Kris Watson <kris@wtsn.io>
@kwatson
kwatson merged commit 1cbd818 into main Aug 13, 2026
5 checks passed
@kwatson
kwatson deleted the codex/release-automation branch August 13, 2026 00:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant