c5093818ae
Rewire OTA publishing off the legacy ota1 box onto the S3-backed denis service, in two places: - Prod path (bundle-deploy-eas-update.yml): dual-write the exported bundle to denis via `denis publish` alongside the existing ota1 upload, under the identical `!includes-changes && !version-changed` gate. Assumes the main-only `denis-ci-publish` role via OIDC (id-token: write). Both paths must succeed; they are removed together once denis is the sole origin. - Per-PR previews (pull-request-commit.yml): replace the `@github-actions ota` comment trigger (pull-request-comment.yml, deleted) with an automatic job that fires on pull_request. Gated to same-repo PRs (head.repo.full_name == github.repository) authored by a MEMBER/OWNER/COLLABORATOR, so a fork or external contributor can never run with the publish role or repo secrets in scope. Publishes to the `pull-request-<N>` channel under the PR-scoped `denis-ci-publish-pr` role, further narrowed by an inline session policy to `pr/<N>/*`. - setup-denis composite action: mint a short-lived github-app token (contents:read on private tango), download + verify the pinned denis release binary, put it on PATH. denis release tag is a single `DENIS_RELEASE_TAG` env per workflow. ROAST_SKIP: pre-commit roast flags setup-denis verifying the binary against a checksum from the same tango release (no independent digest anchor). Reviewed and accepted: exploitation requires compromising the private tango release itself, and the marginal integrity gain is not worth pinning a digest that must be bumped on every denis roll. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Tool Scripts
updateExtensions.sh
Updates the extensions in /modules with the current iOS/Android project changes.