Repository navigation
fix(kilo-app): release token for tag pushes, full CocoaPods inventory in the iOS SBOM - #6741
Conversation
GitHub refuses a GITHUB_TOKEN tag push when the tagged commit's .github/workflows differs from every branch tip. A workflow change that merges during a release run made the marker push fail before Submit iOS (runs 36206309918 and 36207505706). The cap reads only the marker name and creatordate, so the marker now points at the fetched tip of main.
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe only commit since the previous review ( Resolved Since Previous Review
Files Reviewed (10 files)
Previous Review Summaries (5 snapshots, latest commit 382fd62)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 382fd62)Status: 1 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
Files Reviewed (11 files)
The scoped push-token changes and the new CocoaPods Fix these issues in Kilo Cloud Previous review (commit 9d67659)Status: No Issues Found | Recommendation: Merge Executive SummaryThe latest commits scope Files Reviewed (1 file)
Previous review (commit bf76c8e)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe temporary Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Previous review (commit 3daf005)Status: 2 Issues Found | Recommendation: Address before merge Executive SummaryThe tag-push fix itself is sound (the PAT with Workflows: write is the right remedy for the GITHUB_TOKEN tag-push restriction), but the PR still carries the temporary Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (2 files)
Fix these issues in Kilo Cloud Previous review (commit c3a6f17)Status: No Issues Found | Recommendation: Merge Executive SummaryThe single-file change is correct: the iOS upload marker tag now targets a freshly fetched tip of Verified against context:
Files Reviewed (1 file)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
Replace the marker retarget with a checkout token. The tag pushes in build-and-submit now use KILO_APP_RELEASE_TOKEN, a fine-grained PAT with Contents: write and Workflows: write, so a workflow change that merges during a run no longer blocks the marker or the release tag. Both tags stay on HEAD.
The checkout persisted KILO_APP_RELEASE_TOKEN in .git/config for the whole job, so pnpm install and eas-cli could read it. The checkout keeps GITHUB_TOKEN again. The marker and release tag steps get the token as a step env value and send it through GIT_CONFIG_*, which drops the persisted header.
The IPA Mach-O scan sees only dynamic frameworks, so the iOS SBOM listed 2 native components and missed every statically linked pod. EAS now uploads the build's ios/Podfile.lock (eas.json buildArtifactPaths). The release job downloads it with the IPA, and mobile-sbom.mjs requires --podfile-lock and writes one component per root pod with its version and SPEC CHECKSUMS SHA-1. The report-only comparePodfileLock gap check is removed. The mobile-sbom workflow contract now allows the github.com git config key that the Tag release step uses for its push token.
SPEC CHECKSUMS hashes each pod's podspec, not the code in the IPA. A component hash would claim a provenance it does not have, so the value is now the kilo:sbom:podspec-checksum property. SHA-256 checksums are accepted so a CocoaPods upgrade cannot block a release. Files formatted with oxfmt.
The
Mark the iOS uploadstep failed in runs 36206309918 and 36207505706. The failure stopped both store submissions.Cause
GITHUB_TOKENtag push if the tagged commit's.github/workflowsdiffers from every branch tip (community #151442).kilo-app-release.ymlwhile both runs built.Tag releasehas the same exposure.Fix
Mark the iOS uploadandTag releasesteps push withsecrets.KILO_APP_RELEASE_TOKEN, a classic PAT with therepoandworkflowscopes. The token is a step env value passed to git throughGIT_CONFIG_*. It is never written to.git/config, sopnpm installandeas-clicannot read it. Run 36212238302 proved this exact push code.HEAD.Verification
pnpm run test:kilo-app-release: 75 of 75 passed.kilo-app-release.yml. The PAT push passed. The same push withGITHUB_TOKENwas refused with the workflows error. The check is removed.iOS SBOM: every CocoaPod
ExpoModulesJSI.framework,hermesvm.framework). The IPA scan can't see statically linked pods.apps/mobile/eas.jsonproduction uploadsios/Podfile.lock(buildArtifactPaths). The release job downloads it with the IPA through the signedbuildArtifactsUrl, and never prints that URL.mobile-sbom.mjsrequires--podfile-lockand writes onepkg:cocoapods/<Name>@<version>component per root pod. The SPEC CHECKSUMS value is thekilo:sbom:podspec-checksumproperty, not a component hash. The report-onlycomparePodfileLockgap check is removed.cocoapods=179(177 lockfile pods + 2 frameworks), both documents pass strict CycloneDX 1.6 checks, and the fake signed token appears 0 times in the output.test:mobile-sbom42/42,test:mobile-artifacts9/9,test:kilo-app-release75/75.eas build --jsonrecord hasbuildArtifactsUrl. EAS serves the single file as plain text, and the curl fallback without the header downloads it. The lockfile gave 177 pods, for exampleReact-Core@0.86.3,hermes-engine@250829098.0.17,RNSentry@8.23.0.SPEC CHECKSUMShashes the podspec, so it is thekilo:sbom:podspec-checksumproperty, not a component hash.buildArtifactsUrland stops before any submission.