Skip to content

K3: the no-code-signing paragraph, and repoint install.sh:295 #55

Description

@qcentic-dev

Part of #23. Spec: ADR 0016 — The 0.1.0 shape, clauses D46.

Phase 4 — Docs and deletions
Blocked by: nothing — can start immediately
Blocks: #58

What

The strongest case in #17's set. grep -ri 'quarantine|xattr|gatekeeper' across every .ts, .mjs and .sh returns zero hits, and today the fact lives in two half-places: install.sh:295 cites a file this effort deletes, and the macOS prerelease checklist asserts the outcome without the reason. ADR 0010 explicitly deferred the question to "Harness distribution planning" — it was answered there, in files about to be deleted.

Blocks T21 (which deletes the checklist) and T29 (which deletes the spec).

Done when

  • docs/contribute/ci-cd.md § The release artifacts records: integrity is published checksums, verified by both install.sh and actana update — not signatures. No Apple notarization, no Windows Authenticode
  • Records why that is safe: the curl | bash path never sets com.apple.quarantine, so Gatekeeper never intervenes. Revisit only if a browser-download distribution is ever added
  • Records the corollary that already cost one review cycle: do not add xattr -dr com.apple.quarantine to actana setup
  • install.sh:295 cites docs/contribute/ci-cd.md instead of "spec"
  • The supply-chain follow-up ticket is cross-linked, so the paragraph reads as a current posture rather than a permanent refusal

Decisions are locked in ADR 0016. If this ticket needs one changed, amend the ADR in the same PR — do not decide it in a comment.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions