• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive-studio / 24568293232 / 1
70%
main: 70%

Build:
DEFAULT BRANCH: main
Ran 17 Apr 2026 01:47PM UTC
Files 458
Run time 22s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Apr 2026 01:44PM UTC coverage: 65.526% (+2.3%) from 63.242%
24568293232.1

push

github

web-flow
feat(ci): sign Windows prereleases with Azure Trusted Signing (#2032)

* feat(ci): sign Windows prereleases with Azure Trusted Signing

Route Windows prerelease builds (alpha/beta/rc) through the
\`setup-azure-trusted-signing\` composite action instead of DigiCert
KeyLocker, matching the OIDC path already validated in
\`pr-build-test.yml\`. Stable releases keep signing via DigiCert until
the Azure flow is confirmed end-to-end on prereleases.

Scope the \`artifact-signing\` GitHub environment to the Windows matrix
row only (\`matrix.os == 'windows-latest'\` and \`prerelease == true\`)
so Linux/macOS rows and stable Windows releases stay outside the
environment and don't pick up its secrets or approvals. The repo-wide
AWS OIDC trust policy (\`repo:stacklok/toolhive-studio:*\`) already
covers the new \`environment:artifact-signing\` subject, so S3 sync
and CloudFront invalidation keep working from the Windows prerelease
job.

* docs: note Azure Trusted Signing is used for Windows prereleases

Clarify that Azure Trusted Signing is now wired into both
\`pr-build-test.yml\` (via \`/build-test --sign-windows\`) and
\`on-release.yml\` for prerelease tags, and scope the DigiCert
fallback note to stable releases until the migration is completed.

* chore: format

* docs(ci): clarify artifact-signing environment comment

Reword the job-level environment comment so it no longer implies
Linux/macOS rows stay on DigiCert — DigiCert is Windows-only.
Explicitly list the three categories of matrix rows that stay
outside \`artifact-signing\` (Linux any release, macOS any release,
Windows stable) and split the AWS OIDC trust-policy note into its
own paragraph.

Flagged by Copilot review.

3582 of 5980 branches covered (59.9%)

5706 of 8708 relevant lines covered (65.53%)

120.56 hits per line

Source Files on job 24568293232.1
  • Tree
  • List 458
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Build 24568293232
  • 89586ec7 on github
  • Prev Job for on main (#24565367995.1)
  • Next Job for on main (#24574668525.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc