Skip to content

ci: add Zapstore publish pipeline with hardened signing secret handling#144

Merged
justinmoon merged 2 commits into
masterfrom
zapstore
Feb 17, 2026
Merged

ci: add Zapstore publish pipeline with hardened signing secret handling#144
justinmoon merged 2 commits into
masterfrom
zapstore

Conversation

@justinmoon

Copy link
Copy Markdown
Owner

Summary

  • add Android release pipeline support for Zapstore publishing in .github/workflows/release.yml
  • add encrypted Zapstore signing secret workflow (secrets/zapstore-signing.env.age) with age/agenix recipients
  • add Nix-managed zsp tooling and local just recipes for check/publish
  • harden signing-secret handling via scripts/zapstore-publish (xtrace off, temp-file cleanup, masking in GitHub Actions)

Validation

  • ran nix develop .#default -c just pre-merge-pika locally (pass)

Notes

  • bunker migration is intentionally out of scope for this PR

@justinmoon justinmoon merged commit 41a8e54 into master Feb 17, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant