Skip to content

Releases and deployment

Main requires the CI Build Gate, CI build, CI format, Docs build, and Dev shell checks. All jobs use GitHub-hosted ubuntu-24.04 runners, as requested by the maintainer. Each Nix job installs Nix and configures the shared Cachix cache; jobs do not assume a shared machine or store. Build Gate realizes the site, shell, and sandboxed checks before dependent jobs run.

Nix jobs use .github/actions/setup-nix, a local composite action with the supported Nix installer and Cachix v17 (Node.js 24). This replaces the shared helper's retired Node.js 20 cache dependency without suppressing runtime warnings. Keep the tooling regression guard and inspect nested action metadata when updating action versions. Every local action call follows checkout.

All external contributors require workflow approval. Approved fork PRs run on ephemeral GitHub-hosted runners with read-only repository permissions and no repository secrets. They can read the public cache without upload credentials. Administrative bypass is reserved for recovery, not ordinary delivery.

Release-please uses manifest mode for the private Node project. Conventional feat: and fix: commits drive version PRs; maintenance commits accumulate. CI_APP_ID and CI_APP_PRIVATE_KEY mint a repository-scoped token so bot-created PRs trigger CI. They are existing organization settings, not files in this repo. CACHIX_AUTH_TOKEN is also supplied by the organization.

Merging a release PR publishes a GitHub release with fido2box.tar.gz and its SHA-256 checksum. There is no npm publication. A missing app credential fails the release workflow rather than silently creating a PR with suppressed checks.

Pages publishes one artifact: the unbundled app at / and strict MkDocs output at /docs/. COMMIT identifies the source revision. The signed SHA256SUMS manifest covers the app files and commit, preserving source comparisons:

nix develop --quiet -c just verify-live

SITE-SHA256SUMS additionally covers the generated docs and the app manifest and receives a provenance attestation in the same build. To inspect those bytes, download it, verify with gh attestation verify SITE-SHA256SUMS -R lambdasistemi/fido2box, and check its listed files. The weekly app verification remains independently scheduled. Retain ownership of fido2box.dev; changing the RP ID breaks recovery with existing credentials.