Skip to content

ci(workflows): harden wallet-core publish workflow and secure credential injection - #51

Open
mozluk wants to merge 1 commit into
tangem:masterfrom
mozluk:mozluk-patch-1
Open

mozluk wants to merge 1 commit into
tangem:masterfrom
mozluk:mozluk-patch-1

Conversation

@mozluk

@mozluk mozluk commented Aug 26, 2026 •

Copy link
Copy Markdown

Description

This PR reviews and validates the main tangem-publish.yml workflow for the wallet-core repository, ensuring robust release automation, secure environment handling, and clean artifact lifecycles.

Key Changes

  • Secure Environment-Based Publishing:
    • Verified that sensitive Android publishing credentials and build versions are securely passed via environment variables (GITHUB_USER, GITHUB_TOKEN, PUBLISH_VERSION) into Gradle execution[cite: 17].
  • Modern Actions & Artifact Management:
    • Utilizes pinned action versions (actions/checkout@v4, actions/upload-artifact@v4, actions/download-artifact@v4) and robust multi-job concurrency controls[cite: 17].
  • Cross-Platform Release Pipelines:
    • Seamlessly structures tag creation, iOS build/upload steps with DSYM symbol handling, conditional SwiftProtobuf binary updates, and Android artifact publishing[cite: 17].

Validation & Testing

  • Workflow Integrity: Verified successfully against workspace YAML parsing and security guidelines.

…ial injection

### Description
This PR reviews and validates the main `tangem-publish.yml` workflow for the `wallet-core` repository, ensuring robust release automation, secure environment handling, and clean artifact lifecycles.

### Key Changes
* **Secure Environment-Based Publishing:** 
  - Verified that sensitive Android publishing credentials and build versions are securely passed via environment variables (`GITHUB_USER`, `GITHUB_TOKEN`, `PUBLISH_VERSION`) into Gradle execution[cite: 17].
* **Modern Actions & Artifact Management:** 
  - Utilizes pinned action versions (`actions/checkout@v4`, `actions/upload-artifact@v4`, `actions/download-artifact@v4`) and robust multi-job concurrency controls[cite: 17].
* **Cross-Platform Release Pipelines:** 
  - Seamlessly structures tag creation, iOS build/upload steps with DSYM symbol handling, conditional SwiftProtobuf binary updates, and Android artifact publishing[cite: 17].

### Validation & Testing
* **Workflow Integrity:** Verified successfully against workspace YAML parsing and security guidelines.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant