mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 08:13:12 +00:00
* docs: align organization templates with Cursor conventions Refs: PLAT-62 * ci: add deterministic PR policy gate Refs: PLAT-62 * fix(ci): grandfather unchanged workflow policy debt Refs: PLAT-62 * fix(ci): address PR policy security review Refs: PLAT-62 * fix(ci): scan copied workflow files Refs: PLAT-62 * fix(ci): close remaining workflow policy bypasses Refs: PLAT-62 * fix(policy): reject uses block scalar action refs Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(policy): preserve line-specific violation fingerprints Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
21 lines
894 B
YAML
21 lines
894 B
YAML
name: Deploy (iOS / TestFlight)
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
deploy:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4
|
|
with:
|
|
# Pinned explicitly (handbook): local dev is Node 24 / npm 11, which
|
|
# generates lockfileVersion 3. Being explicit avoids lockfile drift.
|
|
node-version: "24"
|
|
secrets:
|
|
# All five are required. deploy-role-arn is the repo's OIDC role, used
|
|
# here to read the fastlane match certificate store from S3; the four
|
|
# asc-*/match-* values come from App Store Connect and the match repo.
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
match-password: ${{ secrets.MATCH_PASSWORD }}
|
|
asc-key-id: ${{ secrets.ASC_KEY_ID }}
|
|
asc-issuer-id: ${{ secrets.ASC_ISSUER_ID }}
|
|
asc-key-content: ${{ secrets.ASC_KEY_CONTENT }}
|