What changed, and why it matters
This commit simply renames four GitHub secret variables used during iOS app release builds, adding an 'IOS_' prefix to each name (for example, 'BUILD_CERTIFICATE_BASE64' becomes 'IOS_BUILD_CERTIFICATE_BASE64'). The workflow still does the exact same thing: it decodes the iOS signing certificate and provisioning profile, creates a temporary keychain, and imports the certificate. There is no change to security behavior, no leaked secrets, and no vulnerability introduced or fixed in the code shown.
No security action required. Ensure the corresponding GitHub repository secrets have been recreated under the new names so iOS release builds continue to work.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch is a pure identifier rename in .github/workflows/release.yml. Environment variables BUILD_CERTIFICATE_BASE64, BUILD_PROVISION_PROFILE_BASE64, P12_PASSWORD, and KEYCHAIN_PASSWORD are renamed to IOS_BUILD_CERTIFICATE_BASE64, IOS_BUILD_PROVISION_PROFILE_BASE64, IOS_P12_PASSWORD, and IOS_KEYCHAIN_PASSWORD respectively, and all shell references are updated. The CI logic, secret handling, and cryptographic operations are unchanged. No credentials are exposed, no permissions change, and no security controls are added or removed.
Changed components
.github/workflows/release.ymlInspect captured patch +9 / −9
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index ab86b12..e3f5d46 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -266,21 +266,21 @@ jobs:
- name: Import code signing
env:
- BUILD_CERTIFICATE_BASE64: ${{ secrets.BUILD_CERTIFICATE_BASE64 }}
- BUILD_PROVISION_PROFILE_BASE64: ${{ secrets.BUILD_PROVISION_PROFILE_BASE64 }}
- P12_PASSWORD: ${{ secrets.P12_PASSWORD }}
- KEYCHAIN_PASSWORD: ${{ secrets.KEYCHAIN_PASSWORD }}
+ IOS_BUILD_CERTIFICATE_BASE64: ${{ secrets.IOS_BUILD_CERTIFICATE_BASE64 }}
+ IOS_BUILD_PROVISION_PROFILE_BASE64: ${{ secrets.IOS_BUILD_PROVISION_PROFILE_BASE64 }}
+ IOS_P12_PASSWORD: ${{ secrets.IOS_P12_PASSWORD }}
+ IOS_KEYCHAIN_PASSWORD: ${{ secrets.IOS_KEYCHAIN_PASSWORD }}
run: |
CERTIFICATE_PATH=$RUNNER_TEMP/build_certificate.p12
PP_PATH=$RUNNER_TEMP/build_pp.mobileprovision
KEYCHAIN_PATH=$RUNNER_TEMP/app-signing.keychain-db
- echo -n "$BUILD_CERTIFICATE_BASE64" | base64 --decode -o $CERTIFICATE_PATH
- echo -n "$BUILD_PROVISION_PROFILE_BASE64" | base64 --decode -o $PP_PATH
- security create-keychain -p "$KEYCHAIN_PASSWORD" $KEYCHAIN_PATH
+ echo -n "$IOS_BUILD_CERTIFICATE_BASE64" | base64 --decode -o $CERTIFICATE_PATH
+ echo -n "$IOS_BUILD_PROVISION_PROFILE_BASE64" | base64 --decode -o $PP_PATH
+ security create-keychain -p "$IOS_KEYCHAIN_PASSWORD" $KEYCHAIN_PATH
security set-keychain-settings -lut 21600 $KEYCHAIN_PATH
security list-keychains -d user -s $KEYCHAIN_PATH
- security import $CERTIFICATE_PATH -P "$P12_PASSWORD" -A -t cert -f pkcs12 -k $KEYCHAIN_PATH
- security set-key-partition-list -S apple-tool:,apple: -k "$KEYCHAIN_PASSWORD" $KEYCHAIN_PATH
+ security import $CERTIFICATE_PATH -P "$IOS_P12_PASSWORD" -A -t cert -f pkcs12 -k $KEYCHAIN_PATH
+ security set-key-partition-list -S apple-tool:,apple: -k "$IOS_KEYCHAIN_PASSWORD" $KEYCHAIN_PATH
mkdir -p ~/Library/MobileDevice/Provisioning\ Profiles
cp $PP_PATH ~/Library/MobileDevice/Provisioning\ Profiles/build_pp.mobileprovision
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.