Skip to content

feat(release): sign Windows artifacts with Azure - #141

Open
SunkenInTime wants to merge 1 commit into
mainfrom
codex/windows-artifact-signing
Open

feat(release): sign Windows artifacts with Azure#141
SunkenInTime wants to merge 1 commit into
mainfrom
codex/windows-artifact-signing

Conversation

@SunkenInTime

@SunkenInTime SunkenInTime commented Aug 30, 2026

Copy link
Copy Markdown
Owner

Summary

  • authenticate GitHub Actions to Azure through OIDC
  • sign the Windows app, bundled FFmpeg/runtime DLLs, and installer with Artifact Signing
  • hash the updater archive only after signing, then verify every Authenticode signature before publication
  • parse all release PowerShell scripts in Windows CI

Verification

  • workflow YAML parsing and release-step ordering checks pass locally
  • fvm flutter analyze --no-fatal-infos passes with one pre-existing deprecation info
  • Windows CI analysis and PowerShell parsing pass
  • Windows CI reaches 429 passing tests and 1 skipped test; its two failures are the same migration-version assertions already failing on current main: https://github.com/SunkenInTime/icarus/actions/runs/31983055496

The release workflow is intentionally restricted to manual dispatches from main, matching the federated credential.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 02bd000a-b45a-4184-bc54-67c21ae580a6

📥 Commits

Reviewing files that changed from the base of the PR and between d7354a4 and 366c9fb.

📒 Files selected for processing (4)
  • .github/workflows/ci.yml
  • .github/workflows/release-desktop.yml
  • scripts/build_desktop_release.ps1
  • scripts/release_desktop.ps1

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The desktop release now uses separate build, package, and stage phases. The workflow signs Windows binaries and the installer with Azure-based Authenticode signing, verifies signatures, and publishes only from main. CI validates PowerShell syntax.

Changes

Desktop release pipeline

Layer / File(s) Summary
Phase-aware release scripts
scripts/build_desktop_release.ps1, scripts/release_desktop.ps1
The scripts support all, build, package, and stage phases. Package validation checks archives, FFmpeg hashes, and size limits. Staging requires the signed installer and copies it to release paths.
Signed Windows release workflow
.github/workflows/release-desktop.yml
The workflow enforces the main branch, authenticates with Azure OIDC, signs release files and the installer, verifies Authenticode signatures, and runs phased release commands.
PowerShell script validation
.github/workflows/ci.yml
CI parses PowerShell files under scripts and installer and fails when parse errors exist.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: ⚪ Minimal · up to 366c9

The release changes are merge-ready after normal checks and review; no actionable merge-blocking risk remains.

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant release_desktop.ps1
  participant AzureOIDC
  participant ArtifactSigning
  participant AuthenticodeVerification
  GitHubActions->>release_desktop.ps1: Run build phase
  GitHubActions->>AzureOIDC: Authenticate with OIDC
  GitHubActions->>ArtifactSigning: Sign release binaries
  GitHubActions->>release_desktop.ps1: Run package phase
  GitHubActions->>ArtifactSigning: Sign installer
  GitHubActions->>AuthenticodeVerification: Verify signatures
  GitHubActions->>release_desktop.ps1: Run stage phase
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: signing Windows release artifacts with Azure Artifact Signing.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (4 skipped: 4 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/windows-artifact-signing

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This change adds Azure OIDC-based signing to the Windows desktop release workflow. Release executables and DLLs are signed before updater hashes are generated, installers are signed and checked before the workflow publishes them, and releases started from non-main branches stop before Azure login.

The hosted release path has the intended protections, but the local prerelease publishing script can still publish an installer without Azure signing or Authenticode validation.

T-Rex validation blocked

Live Windows signing and Authenticode verification could not run because the environment is missing the Windows runner service and Windows PowerShell/Authenticode tools. Control-flow and ordering checks were executed instead. Configure VMs

Confidence Score: 4/5

The hosted Windows release workflow is protected, but the local prerelease publishing route can expose an unsigned installer.

Executable ordering and cross-script reachability checks verified all investigated release paths. Native Windows signing and Authenticode validation could not run without a Windows environment, but the local publication bypass is directly established by the release scripts.

Files Needing Attention: scripts/publish_prerelease_local.ps1, scripts/release_desktop.ps1, and scripts/build_desktop_release.ps1 need a mandatory signing-validation gate or publication restriction.

Security Review

Do not merge until local prerelease publication is protected. scripts/publish_prerelease_local.ps1 enables Pages publication through the shared PowerShell release path, which does not perform Azure signing or validate Authenticode status before placing the installer in the public prerelease downloads location. The GitHub-hosted release workflow correctly signs release binaries before packaging, rejects invalid signatures before publication, and blocks non-main runs before Azure login.

T-Rex T-Rex Logs

What T-Rex did

  • T-Rex compared the former archive path with the changed workflow and verified that release-binary signing occurs before package creation and that the signed release snapshot is copied before updater hashes are generated.
  • T-Rex compared the former direct publication route with the changed workflow and performed a workflow control-flow assertion that binary and installer signing precede signature rejection and publication; a live Authenticode check could not run because Windows PowerShell and Windows artifacts are unavailable in this environment.
  • T-Rex compared the main-branch baseline workflow with the changed branch gate and executed the non-main dispatch predicate for refs/heads/release-candidate; the predicate fails before Azure login and before either signing action can run.
  • T-Rex described the release flow changes, noting that the Sign Windows Release Binaries step precedes the Build Signed Updater Archive And Installer step and that the Release snapshot is copied before updater hash generation; the after-check confirmed these two ordering truths.
  • T-Rex captured the Windows signing gate runtime blocker logs and related excerpts and produced proofs for posted P1 findings (see review comments).

View all artifacts

T-Rex Ran code and verified through T-Rex

Comments Outside Diff (2)

  1. scripts/publish_prerelease_local.ps1, line 15-35 (link)

    P1 security Local prerelease publisher bypasses signing verification

    The local prerelease entry point enables Pages publication and reaches the shared release flow without the workflow-only Azure Artifact Signing actions or Get-AuthenticodeSignature check. The shared build path only checks that the installer exists before copying it into the publishable downloads directory, so an unsigned installer can be force-published to the public prerelease channel.

    T-Rex Ran code and verified through T-Rex

  2. General comment

    P1 Local prerelease publisher bypasses Azure signing and Authenticode verification

    • Bug
      • Running scripts/publish_prerelease_local.ps1 invokes the full desktop release flow with Pages publishing enabled. It can build an installer, stage it, and force-push downloads/windows/prerelease to GitHub Pages without passing through the workflow-only Azure signing actions or the workflow-only Get-AuthenticodeSignature verification. This allows an unsigned installer to be publicly published to the prerelease channel.
    • Cause
      • Signing and verification were added exclusively to .github/workflows/release-desktop.yml:85-163. The reusable/local PowerShell release path has no equivalent signing or validation gate: scripts/publish_prerelease_local.ps1:15-35 forces publication, scripts/release_desktop.ps1:83-124 invokes the build and publisher, and scripts/build_desktop_release.ps1:207-231 tests only installer presence before copying it to publishable paths.
    • Fix
      • Restrict publication to the signed GitHub Actions workflow, or add a mandatory signature-validation gate to the shared PowerShell release flow immediately before staging/copying the installer and before publish_pages_branch.ps1 is invoked. The gate must fail when every publishable EXE does not have Authenticode status Valid.

    T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "feat(release): sign Windows artifacts wi..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant