Prepare secure v0.1.0 release - #18
Conversation
独立用户验收入口正式 v0.1.0 Tag 尚未创建。请只测试这个不可变候选 commit: https://github.com/jiangsir-tech/codex-bark-notifier/tree/fca0eefa52becaabd8a702956916bdf8ddb92ea6 把下面内容复制给 Mac 上的 Codex 本地任务,并把最后一行换成测试者自己的 Bark Device Key: 请直接在这台 Mac 上安装、验证并随后安全卸载 Codex Bark Notifier 候选版本,不要只给操作说明。只使用上面的固定 commit,不要改用 main,也不要使用尚不存在的 v0.1.0 Tag。 先阅读该 commit 中的 README、SECURITY、安装指南和安装器帮助。运行完整 verify 和 dry-run,确认不覆盖原有 notify 或其他 Hooks;再通过交互式隐藏输入把 Device Key 交给安装器,不要在命令、日志或回复里显示。安装后只发送一条测试通知,由我确认 iPhone 是否收到;再引导我在 Codex CLI 的 /hooks 中人工核对 PermissionRequest Hook,不得自动信任或批准。 确认安装工作后,运行默认的可恢复卸载,不得使用 purge。核对原有 notify、其他 Hooks 和后来配置都保留或恢复,私有 Key、公开配置、日志和备份按设计保留。最后报告 macOS、Codex/ChatGPT、Node.js 来源与版本、测试数量、安装与卸载结果、手机实收结果、Hook 状态和任何异常。不要提交或推送仓库。 我的 Bark Device Key: 验收通过后,再将 PR 转为 Ready、合并并创建不可移动的 v0.1.0 Tag/Release。 |
Summary
Verification
Release decision
The owner explicitly waived independent-user validation for v0.1.0 and accepted the risk of fixing real-world issues in follow-up releases. Release notes must disclose that no independent macOS plus Bark user completed the install and uninstall flow before publication. The immutable release archive will still be downloaded and retested before the GitHub Release is published.