Add the package verifier and run it before release builds - #387
Conversation
Issue #356 asks for scripts/verify-package.mjs, wired into release.yml before the platform builds. It needs product and key-custody decisions before it can assert everything the Phase 7 plan lists, so it enforces what the configuration, README and capability guard already agree on and reports the rest as pending: - enforced: product name and identifier; the 1180x780 default and the documented 480x520 minimum window; withGlobalTauri off; a strict CSP with no unsafe-eval, no wildcard or scheme sources and no network origin in connect-src; the six installer targets and five icons, present on disk; the main window's exact capability allowlist; no shell, filesystem, HTTP, opener or process plugin. - pending (issue #356 decisions 2 and 3): the updater public key with updater artifacts on, and the opencoven-chat protocol. --release makes them failures for when they are decided; release.yml does not pass it yet, since docs/releasing.md documents the updater as opt-in and off. The minimum window follows the implemented contract (README, responsive tiers) rather than the plan's older 820x600, per the evidence on #356. Tests pass the real configuration and fail each of thirteen mutations. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved verifier correctness, capability coverage, documentation, and workflow-test issues remain.
Review effort: Lite
Findings: 2
Open (5)
What changed in this PR
Adds a Tauri package-contract verifier, tests, release workflow integration, and documentation for pre-build validation.
Changes:
- Validates configuration, CSP, capabilities, icons, targets, and plugins.
- Reports updater and deep-link decisions as pending.
- Adds mutation tests and runs verification before release builds.
- Documents local verification and release checks.
| File | Reviewed changes | Findings |
|---|---|---|
src/verify-package.test.ts |
Adds verifier mutation tests. | No findings. |
scripts/verify-package.mjs |
Implements package-contract validation. | Unresolved CSP duplicate handling, missing connect-src, deep-link validation, and incomplete capability-file coverage. |
docs/releasing.md |
Documents verification and release requirements. | Updater checklist requirements contradict the documented opt-in state. |
.github/workflows/release.yml |
Runs verification before release builds. | Workflow tests do not assert the verifier step or its ordering. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- A repeated CSP directive is rejected: the first copy stays in force, so checking only one could pass a permissive policy. - connect-src is required, with ipc: and http://ipc.localhost; without it default-src 'self' blocks the webview's IPC to its own host. - Every capability file is read, and any file other than the reviewed default.json fails, since Tauri loads them all. - The protocol counts as registered only at plugins.deep-link.desktop.schemes, not wherever the string appears. - The release workflow test pins the verifier step in verify-tag, after checkout and before the tag check, ahead of the build job. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
The release owner's decisions on #356 are now recorded there. One affects this PR. The |
The three open decisions are now made (2026-09-26): the window minimum stays 480x520, the opencoven-chat protocol is deferred past v0.0.1, and the updater stays off for v0.0.1. With nothing left pending, the verifier drops its pending list and --release flag and enforces the decided state: createUpdaterArtifacts false with no updater config or crate, and no deep-link config or crate. A release that enables either changes the decision here in the same change that configures it. The workflow comment and docs/releasing.md say so. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>


Refs #356. This does the verifier part of the issue and encodes its decisions. It does not close the issue, because the signing secrets are still needed (decision 4).
What #356 asks
scripts/verify-package.mjs, wired intorelease.ymlbefore the platform builds.Decisions (made 2026-09-26, recorded on #356)
docs/releasing.md§ 4 already documents.What the verifier enforces
OpenCoven Chatand identifierai.opencoven.chat.main, with a 1180×780 default and a 480×520 minimum;withGlobalTauri: false.default-srcandscript-srcare'self', andobject-src,base-uri,form-actionandframe-ancestorsare'none'. Nounsafe-eval,*,http:orhttps:source is allowed.connect-srcis required and holds only'self',ipc:andhttp://ipc.localhost. Repeated directives are rejected.bundle.active, the six installer targets, and the five declared icons, which must exist on disk.default.jsonmay exist. It must grant exactly the reviewed allowlist tomain, with no remote origins and no shell, fs, opener, http, process, os or dialog permission.tauri-plugin-shell,-fs,-http,-openeror-processinCargo.toml.createUpdaterArtifacts: falsewith no updater config or crate, and no deep-link config or crate. A release that enables either changes that decision in the same change that configures it.Wiring and docs
release.yml,verify-tagjob: runs after checkout and before the tag check, so before every platform build, on rehearsal and production paths.release-workflow.test.tspins the step and its position.docs/releasing.md§ 1: the checklist says what it enforces.Remaining on #356
Decision 4: the Apple Developer ID and notarization credentials and the Windows code-signing certificate in the
release-signingenvironment, which holds no secrets today. Then push a signedv0.0.1(or-rc.N) tag.Verification
src/verify-package.test.ts, 23 tests. The real configuration passes. Each mutation below fails:unsafe-eval, a network origin, a repeatedconnect-src, and a missingconnect-src;release-workflow.test.tspins the step's position. Biome and typecheck are clean..github/workflows.🤖 Generated with Claude Code