.github/workflow-templates/mobile-ios-deploy.yml
Adam Moussa 9c1ecf9428
Some checks are pending
ci / ci / ci (push) Waiting to run
Release on reusable change / version (push) Waiting to run
Release on reusable change / release (push) Blocked by required conditions
ci: add deterministic PR policy and align org templates (PLAT-62) (#115)
* docs: align organization templates with Cursor conventions

Refs: PLAT-62

* ci: add deterministic PR policy gate

Refs: PLAT-62

* fix(ci): grandfather unchanged workflow policy debt

Refs: PLAT-62

* fix(ci): address PR policy security review

Refs: PLAT-62

* fix(ci): scan copied workflow files

Refs: PLAT-62

* fix(ci): close remaining workflow policy bypasses

Refs: PLAT-62

* fix(policy): reject uses block scalar action refs

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

* fix(policy): preserve line-specific violation fingerprints

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-08-03 20:30:32 -04:00

21 lines
894 B
YAML

name: Deploy (iOS / TestFlight)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4
with:
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
node-version: "24"
secrets:
# All five are required. deploy-role-arn is the repo's OIDC role, used
# here to read the fastlane match certificate store from S3; the four
# asc-*/match-* values come from App Store Connect and the match repo.
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
match-password: ${{ secrets.MATCH_PASSWORD }}
asc-key-id: ${{ secrets.ASC_KEY_ID }}
asc-issuer-id: ${{ secrets.ASC_ISSUER_ID }}
asc-key-content: ${{ secrets.ASC_KEY_CONTENT }}