Standardize BonsAI branding, CI, and signed releases#92
Merged
Conversation
ojowwalker77
marked this pull request as ready for review
July 17, 2026 03:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ojowwalker77/BonsAIand removes stalekiwi-init/BonsAIintegration linksbootstrap,run,check,verify, andrelease-preflightdeveloper contractQualityaggregatemainWhy
The installed app was still checking an upstream repository for updates, and the release workflow could publish unsigned, unnotarized artifacts when credentials were missing. Developer and release commands also differed from the shared contract planned for TeaCode, BonsAI, and Lua Browser.
This gives BonsAI a single reproducible path from checkout to a trusted public release without renaming the internal
ComposerSwift module or storage paths in this PR.User and developer impact
Users receive the coordinated app icon and updates from the correct repository. Public downloads can no longer silently degrade to unsigned builds.
Contributors can use:
Maintainers must configure the standardized release secrets documented in
docs/releasing.mdbefore the next release.Validation
./script/bootstrap./script/check— release build and 169 tests, all passing./script/verifyBONSAI_VERIFY_EXISTING=1 ./script/verify./script/release-preflight 1.4.7git diff --checkThe actual Developer ID signing/notarization job requires repository secrets and is intentionally left to the draft PR checks or a controlled release run.