CI: pin iOS signing certificate by SHA-1 and log CI keychain identities

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
Ayushya Amitabh
2026-10-07 23:14:07 -04:00
co-authored by Claude Sonnet 5.5
parent ef4c1a2afa
commit 91ab8b4a07
3 changed files with 11 additions and 3 deletions
+7 -2
View File
@@ -6,6 +6,11 @@
require "xcodeproj"
TEAM = "Q3JLTAG9PV"
# Pinned by SHA-1, not by the "Apple Distribution" name: a runner that also
# holds other same-named distribution certs (e.g. a dev Mac's login keychain)
# would otherwise let Xcode pick one the profiles don't include. Update this
# (and ios/ExportOptions.plist) when the certificate is renewed.
CERT_SHA1 = "2527806871D806E8E27221B15CA8A1938CF216F2"
PROFILES = {
"Runner" => "NooProfile",
"ShareExtension" => "NooShareSheetProfile",
@@ -18,8 +23,8 @@ PROFILES.each do |target_name, profile|
settings = config.build_settings
settings["CODE_SIGN_STYLE"] = "Manual"
settings["DEVELOPMENT_TEAM"] = TEAM
settings["CODE_SIGN_IDENTITY"] = "Apple Distribution"
settings["CODE_SIGN_IDENTITY[sdk=iphoneos*]"] = "Apple Distribution"
settings["CODE_SIGN_IDENTITY"] = CERT_SHA1
settings["CODE_SIGN_IDENTITY[sdk=iphoneos*]"] = CERT_SHA1
settings["PROVISIONING_PROFILE_SPECIFIER"] = profile
end
end