Shared GitHub Actions for Astral projects.
- Release smoke test: test release artifacts in disposable containers.
- PR security review: review pull requests with Codex Security.
- Plan release signing: derive native verification matrices and artifact declarations from cargo-dist targets.
- Prepare release signing inputs: extract executables and check that wheels and GitHub archives agree.
- macOS signing: Azure authentication, signing, and notarization.
- Windows signing: Azure authentication, signing, and publisher and timestamp verification.
- Assemble signed releases: inject signed executables into wheels and GitHub archives, updating records and checksums.
- Verify signed releases: check packaged bytes and signatures on native runners.
- Verify packaged binaries: use the same native checks with a project's own archive adapter.
The caller supplies package executable inventories, release approval, artifact transfers, and project-specific smoke tests. Use the same pinned commit for all actions in a release.