feat: embed app extensions in macOS app releases - #14
Merged
Merged
Conversation
A new app-extensions input lists SwiftPM executables to ship as Contents/PlugIns/<name>.appex (for example a WidgetKit widget). Each is checked up front (Info.plist names the executable and declares an extension point; entitlements exist), built arm64-only, stamped with the app's version and build number, and signed with its own entitlements before the app is signed over it, in both the Developer ID and ad-hoc paths. Verification is now --deep so a badly signed extension fails the run. Binaries are located with swift build --show-bin-path rather than a hardcoded .build/arm64-apple-macosx path, which newer toolchains no longer use. Callers that don't set app-extensions get the same bundle as before.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved moderate issues affect extension stamping, resource packaging, and required linker flags.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds optional app-extension packaging, signing, and verification to the reusable macOS release workflow.
Changes:
- Validates, builds, bundles, versions, signs, and verifies extensions.
- Uses SwiftPM’s discovered binary path and deep signature verification.
- Documents the new
app-extensionsinput.
| File | Summary |
|---|---|
.github/workflows/macos-app-release.yml |
Implements extension assembly and signing. Moderate findings: missing version keys can cause stamping to fail, and extension resources are not copied. |
docs/releasing-macos-apps.md |
Documents extension configuration. Moderate finding: documented linker flags are not applied or validated. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+233
to
+234
| /usr/libexec/PlistBuddy -c "Set :CFBundleShortVersionString $VERSION" "$appex/Contents/Info.plist" | ||
| /usr/libexec/PlistBuddy -c "Set :CFBundleVersion $BUILD" "$appex/Contents/Info.plist" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What
A new optional
app-extensionsinput onmacos-app-release.ymlfor shipping app extensions (for example, Sitrep's WidgetKit widget) inside the.app.Each line is
<executable> <info-plist> <entitlements>. For each extension, the workflow:NSExtension:NSExtensionPointIdentifier, and that the entitlements file exists, before buildingContents/PlugIns/<executable>.appex, stamped with the app's version and build numberSignature verification is now
--deep.Binaries are located with
swift build --show-bin-pathinstead of the hardcoded.build/arm64-apple-macosx/releasepath, which the Xcode 27 toolchain no longer uses.Callers that don't set
app-extensionsget the same bundle as before.Testing
actionlintpasses.--deepverify passesapp-extensionsline: the run fails early with a clear errorThe runbook (
docs/releasing-macos-apps.md) documents the new input.