Skip to content

fix(kilo-app): release token for tag pushes, full CocoaPods inventory in the iOS SBOM - #6741

Merged
iscekic merged 11 commits into
mainfrom
fix/kilo-app-upload-marker-race
Sep 28, 2026
Merged

iscekic merged 11 commits into
mainfrom
fix/kilo-app-upload-marker-race

Conversation

@iscekic

@iscekic iscekic commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

The Mark the iOS upload step failed in runs 36206309918 and 36207505706. The failure stopped both store submissions.

Cause

Fix

  • The Mark the iOS upload and Tag release steps push with secrets.KILO_APP_RELEASE_TOKEN, a classic PAT with the repo and workflow scopes. The token is a step env value passed to git through GIT_CONFIG_*. It is never written to .git/config, so pnpm install and eas-cli cannot read it. Run 36212238302 proved this exact push code.
  • Both tag steps are unchanged and stay on HEAD.
  • No workflow runs on a tag push, so tags pushed with the PAT start no runs.

Verification

  • pnpm run test:kilo-app-release: 75 of 75 passed.
  • A temporary check (run 36211069897, attempt 3) pushed a tag on a new commit that changed kilo-app-release.yml. The PAT push passed. The same push with GITHUB_TOKEN was refused with the workflows error. The check is removed.

iOS SBOM: every CocoaPod

  • Before: the iOS SBOM listed 2 native components (ExpoModulesJSI.framework, hermesvm.framework). The IPA scan can't see statically linked pods.
  • apps/mobile/eas.json production uploads ios/Podfile.lock (buildArtifactPaths). The release job downloads it with the IPA through the signed buildArtifactsUrl, and never prints that URL.
  • mobile-sbom.mjs requires --podfile-lock and writes one pkg:cocoapods/<Name>@<version> component per root pod. The SPEC CHECKSUMS value is the kilo:sbom:podspec-checksum property, not a component hash. The report-only comparePodfileLock gap check is removed.
  • Smoke test on the released 1.0.12 IPA and AAB with a real local Podfile.lock: exit 0, iOS cocoapods=179 (177 lockfile pods + 2 frameworks), both documents pass strict CycloneDX 1.6 checks, and the fake signed token appears 0 times in the output.
  • Tests: test:mobile-sbom 42/42, test:mobile-artifacts 9/9, test:kilo-app-release 75/75.
  • EAS proof from this branch (run 36213666349, a production iOS build with no submission): the eas build --json record has buildArtifactsUrl. EAS serves the single file as plain text, and the curl fallback without the header downloads it. The lockfile gave 177 pods, for example React-Core@0.86.3, hermes-engine@250829098.0.17, RNSentry@8.23.0.
  • SPEC CHECKSUMS hashes the podspec, so it is the kilo:sbom:podspec-checksum property, not a component hash.
  • Only builds made after this merge upload the Podfile.lock. A rerun of an older commit has no buildArtifactsUrl and stops before any submission.

GitHub refuses a GITHUB_TOKEN tag push when the tagged commit's
.github/workflows differs from every branch tip. A workflow change that
merges during a release run made the marker push fail before Submit iOS
(runs 36206309918 and 36207505706). The cap reads only the marker name and
creatordate, so the marker now points at the fetched tip of main.
@kilo-code-bot

kilo-code-bot Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

The only commit since the previous review (382fd62c) deletes the temporary EAS Podfile.lock diagnostic workflow, resolving the prior WARNING; no temp workflows remain and no new issues are present in the current HEAD (80ae363e).

Resolved Since Previous Review

File Previous Issue Resolution
.github/workflows/tmp-podfile-lock-proof.yml WARNING: temporary diagnostic workflow must be removed before merge File deleted in 80ae363e; no tmp-* workflow remains in the PR diff
.github/workflows/tmp-release-token-check.yml WARNING: temporary diagnostic workflow must be removed before merge File no longer in the PR diff
Files Reviewed (10 files)
  • .github/workflows/kilo-app-release.yml
  • apps/mobile/eas.json
  • docs/sbom.md
  • scripts/inspect-mobile-artifacts.mjs
  • scripts/inspect-mobile-artifacts.test.mjs
  • scripts/mobile-sbom-ipa.mjs
  • scripts/mobile-sbom-ipa.test.mjs
  • scripts/mobile-sbom-workflow.test.mjs
  • scripts/mobile-sbom.mjs
  • scripts/mobile-sbom.test.mjs
Previous Review Summaries (5 snapshots, latest commit 382fd62)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 382fd62)

Status: 1 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/tmp-podfile-lock-proof.yml 1 Temporary diagnostic workflow must be removed before merge
Files Reviewed (11 files)
  • .github/workflows/kilo-app-release.yml - no issues
  • .github/workflows/tmp-podfile-lock-proof.yml - 1 issue
  • apps/mobile/eas.json - no issues
  • docs/sbom.md - no issues
  • scripts/inspect-mobile-artifacts.mjs - no issues
  • scripts/inspect-mobile-artifacts.test.mjs - no issues
  • scripts/mobile-sbom-ipa.mjs - no issues
  • scripts/mobile-sbom-ipa.test.mjs - no issues
  • scripts/mobile-sbom-workflow.test.mjs - no issues
  • scripts/mobile-sbom.mjs - no issues
  • scripts/mobile-sbom.test.mjs - no issues

The scoped push-token changes and the new CocoaPods Podfile.lock SBOM logic introduce no further issues. The earlier KILO_APP_RELEASE_TOKEN persistence and temporary token-check findings are resolved (the token now reaches only the two tag pushes via GIT_CONFIG_*, and tmp-release-token-check.yml is deleted).

Fix these issues in Kilo Cloud

Previous review (commit 9d67659)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The latest commits scope KILO_APP_RELEASE_TOKEN to only the two tag-push steps through GIT_CONFIG_* (never persisted to .git/config), so pnpm install and eas-cli cannot read it, and remove the temporary diagnostic workflow. Both prior findings are resolved and the changed lines introduce no new issues.

Files Reviewed (1 file)
  • .github/workflows/kilo-app-release.yml

Previous review (commit bf76c8e)

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

The temporary tmp-release-token-check.yml diagnostic workflow flagged in the previous review is removed in the latest commit, but the repo-scoped release PAT remains persisted in the workspace for the entire 60-minute build job.

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 1
Issue Details (click to expand)

SUGGESTION

File Line Issue
.github/workflows/kilo-app-release.yml 240 Repo-scoped PAT persisted by checkout for the whole 60-minute job
Files Reviewed (2 files)
  • .github/workflows/kilo-app-release.yml - 1 issue
  • .github/workflows/tmp-release-token-check.yml - removed; previous WARNING resolved

Fix these issues in Kilo Cloud

Previous review (commit 3daf005)

Status: 2 Issues Found | Recommendation: Address before merge

Executive Summary

The tag-push fix itself is sound (the PAT with Workflows: write is the right remedy for the GITHUB_TOKEN tag-push restriction), but the PR still carries the temporary tmp-release-token-check.yml workflow the description says to revert before merge, and the new fine-grained PAT is persisted in the workspace for the entire build job.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/tmp-release-token-check.yml 1 Temporary diagnostic workflow with contents: write must be removed before merge

SUGGESTION

File Line Issue
.github/workflows/kilo-app-release.yml 240 Repo-scoped PAT persisted by checkout for the whole 60-minute job
Files Reviewed (2 files)
  • .github/workflows/kilo-app-release.yml - 1 issue
  • .github/workflows/tmp-release-token-check.yml - 1 issue

Fix these issues in Kilo Cloud

Previous review (commit c3a6f17)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The single-file change is correct: the iOS upload marker tag now targets a freshly fetched tip of main (FETCH_HEAD) instead of HEAD, which resolves the GITHUB_TOKEN workflow-scope tag-push rejection while preserving the cap ledger semantics that read only the marker name and creatordate.

Verified against context:

  • Only .github/workflows/kilo-app-release.yml changed (7 insertions, 1 deletion).
  • scripts/kilo-app-release-upload-cap.mjs reads only %(refname:short) and %(creatordate:unix), so retargeting the annotated tag does not change the upload count.
  • build-and-submit inherits top-level permissions: contents: write, so the added git fetch and existing git push remain authorized.
  • The job is gated on github.ref == 'refs/heads/main', so origin main always exists for the fetch.
  • bash -e aborts the step if the fetch fails, which keeps the "no marker, no submission" safety invariant.
Files Reviewed (1 file)
  • .github/workflows/kilo-app-release.yml

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Replace the marker retarget with a checkout token. The tag pushes in
build-and-submit now use KILO_APP_RELEASE_TOKEN, a fine-grained PAT with
Contents: write and Workflows: write, so a workflow change that merges during
a run no longer blocks the marker or the release tag. Both tags stay on HEAD.
@iscekic iscekic changed the title fix(kilo-app): tag the iOS upload marker at the tip of main fix(kilo-app): push release tags with a token that has Workflows: write Sep 26, 2026
@iscekic
iscekic marked this pull request as draft September 26, 2026 02:15
Comment thread .github/workflows/tmp-release-token-check.yml Outdated
Comment thread .github/workflows/kilo-app-release.yml Outdated
@iscekic
iscekic marked this pull request as ready for review September 26, 2026 02:28
@iscekic
iscekic enabled auto-merge (squash) September 26, 2026 02:35
The checkout persisted KILO_APP_RELEASE_TOKEN in .git/config for the whole
job, so pnpm install and eas-cli could read it. The checkout keeps
GITHUB_TOKEN again. The marker and release tag steps get the token as a step
env value and send it through GIT_CONFIG_*, which drops the persisted header.
The IPA Mach-O scan sees only dynamic frameworks, so the iOS SBOM listed 2
native components and missed every statically linked pod. EAS now uploads the
build's ios/Podfile.lock (eas.json buildArtifactPaths). The release job
downloads it with the IPA, and mobile-sbom.mjs requires --podfile-lock and
writes one component per root pod with its version and SPEC CHECKSUMS SHA-1.
The report-only comparePodfileLock gap check is removed.

The mobile-sbom workflow contract now allows the github.com git config key
that the Tag release step uses for its push token.
@iscekic iscekic changed the title fix(kilo-app): push release tags with a token that has Workflows: write fix(kilo-app): release token for tag pushes, full CocoaPods inventory in the iOS SBOM Sep 26, 2026
SPEC CHECKSUMS hashes each pod's podspec, not the code in the IPA. A
component hash would claim a provenance it does not have, so the value is now
the kilo:sbom:podspec-checksum property. SHA-256 checksums are accepted so a
CocoaPods upgrade cannot block a release. Files formatted with oxfmt.
Comment thread .github/workflows/tmp-podfile-lock-proof.yml Outdated
@iscekic iscekic added the merge-by-human the merge bot routed this PR to a human label Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-by-human the merge bot routed this PR to a human

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants