krz/octosentry

macOS menu bar app to monitor GitHub security alerts github macos menubar security

Commit 89bac7b5f8

89bac7b5f883f276f615e03ac0c6dfe0f3495fcb

parent: a520a4a7f0

Unsigned

cmc <hello@cleberg.net> · 2026-08-22 20:30 UTC
committer: <noreply@github.com>

Add CI workflow running xcodebuild test (#24)

Runs the macOS test scheme on pull_request and push to main.

Pins Xcode 26.1: the runner defaults to 16.4, which rejects
SecurityEventStore's async-let fetches under strict concurrency.

Ad-hoc signing, since the runner has no Developer ID certificate and
the sandbox/hardened-runtime entitlements need a signature for the UI
tests to launch the app.

Also adds the github-actions ecosystem to dependabot, now that there
are workflow action versions to update.

Layout: unified · split

.github/dependabot.yml +5
@@ -9,3 +9,8 @@ updates:
9 directory: "/" # Location of package manifests 9 directory: "/" # Location of package manifests
10 schedule: 10 schedule:
11 interval: "weekly" 11 interval: "weekly"
12
13 - package-ecosystem: "github-actions"
14 directory: "/"
15 schedule:
16 interval: "weekly"
.github/workflows/test.yml added +39
@@ -0,0 +1,39 @@
1name: test
2
3on:
4 pull_request:
5 push:
6 branches: [main]
7
8concurrency:
9 group: test-${{ github.ref }}
10 cancel-in-progress: true
11
12jobs:
13 test:
14 runs-on: macos-15
15 steps:
16 - uses: actions/checkout@v4
17
18 # The runner defaults to Xcode 16.4, whose strict-concurrency checking
19 # rejects SecurityEventStore's async-let fetches. Pin to the newest
20 # Xcode on the image.
21 - name: Select Xcode
22 run: sudo xcode-select -s /Applications/Xcode_26.1.app
23
24 - name: Show toolchain
25 run: xcodebuild -version
26
27 # Ad-hoc signing: the runner has no Developer ID certificate, and the
28 # app's sandbox/hardened-runtime entitlements need a signature to be
29 # applied at all. Building fully unsigned makes the UI tests fail to
30 # launch the app.
31 - name: Test
32 run: |
33 xcodebuild test \
34 -scheme octosentry \
35 -destination 'platform=macOS' \
36 CODE_SIGN_IDENTITY="-" \
37 CODE_SIGN_STYLE=Manual \
38 DEVELOPMENT_TEAM="" \
39 PROVISIONING_PROFILE_SPECIFIER=""