Skip to content

docs(release): record immutable GitHub signing identity - #172

Merged
SunkenInTime merged 1 commit into
mainfrom
codex/signing-immutable-subject
Sep 20, 2026
Merged

SunkenInTime merged 1 commit into
mainfrom
codex/signing-immutable-subject

Conversation

@SunkenInTime

Copy link
Copy Markdown
Owner

The signing credential expects GitHub owner and repository IDs in the OIDC subject. Document the repository setting and exact subject after correcting the mismatch that caused AADSTS700213. Azure login now succeeds in unpublished release run 35534131893. Validation: git diff --check and live GitHub OIDC settings readback.

@coderabbitai

coderabbitai Bot commented Sep 20, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 47 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 65208e2a-b9f4-46fc-91f3-34ac6dd0f895

📥 Commits

Reviewing files that changed from the base of the PR and between 87ec577 and 47e3f1e.

📒 Files selected for processing (1)
  • docs/release_process.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

Safe to merge: the release-signing guidance matches the repository's active immutable OIDC configuration and the desktop release workflow.

What we checked:

  • Immutable OIDC subject rejects release authentication: GitHub reports the documented numeric owner and repository IDs, immutable subject prefix, and main default branch. The desktop workflow grants an ID token, rejects non-main runs before Azure login, and uses the documented Azure audience contract. T-Rex
  • Compared the legacy OIDC subject with the immutable-subject guidance and validated the key identifiers by querying GitHub's live repository metadata and the OIDC customization endpoint. T-Rex
  • Verified that the Release Desktop workflow’s identity matches the documented subject and that all focused assertions passed. T-Rex
  • Reviewed repository, documentation, and workflow evidence to confirm the exact subject construction and the validation results; the evidence excerpts and the check outcomes are summarized in the artifacts. T-Rex

Summary

This update documents the immutable GitHub Actions OIDC identity required for Azure Artifact Signing on desktop releases. The recorded owner ID, repository ID, branch subject, issuer, and audience match the live GitHub repository settings and the Release Desktop workflow.

Reviews (1) · Last reviewed commit: "docs(release): record immutable GitHub s..."

@SunkenInTime
SunkenInTime merged commit 138a8a5 into main Sep 20, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant