1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
- 1Password CLIを導入したいとき
- APIキーをコマンドに渡したいとき
- CIでサービスアカウント認証を使う
OpenClawのmacOS安定版リリースで、署名、Appleの公証、配布ファイルと更新情報の公開を進めます。事前検証や失敗した処理の再開、公開後の確認も扱います。
原文Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
インストール方法を見るOpenClawのmacOS安定版を配布するための検証、署名、Appleの公証、公開確認を進めます。公証はAppleによる配布物の確認手続きです。事前検証と本番公開でタグやソースの一致を確認し、検証済みの配布ファイルをGitHub Releaseへ追加します。自動更新用の配信情報であるappcastの公開と、署名・バージョン情報の確認も扱います。
macOS版の安定版リリースを担当するときや、署名、公証、パッケージ作成で失敗した処理を復旧するときに向いています。失敗時に残ったチェックポイントからの再開や、認証エラーの原因確認にも利用できます。
appcast.xmlを確認して」通常の安定版向けで、extended-stableには使いません。関連するリリース用スキル、1Passwordの認証情報、App Store ConnectのAPIキー、制限付きリリース環境へのアクセスが必要です。認証情報は同じ1Password項目から取得し、公証の認証を検証してから設定します。GitHub環境の承認ルールに従い、本番公開には同じタグ・ソースに対する事前検証と検証の成功記録が必要です。
この紹介文は、公開されている SKILL.md をもとに AI(Claude Haiku)が作成しました。正確な仕様は下の原文を確認してください。
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Use with $release-openclaw-maintainer, $release-openclaw-ci, $one-password, and $release-private if it exists when stable macOS assets, release-ops mac preflight, notarization, appcast promotion, or mac release recovery is involved.
This is a regular stable-release skill. Do not invoke it for extended-stable; that track's GitHub Release carries shared validation evidence but does not inherit macOS assets or appcast promotion.
An explicit stable or full release request includes macOS publication unless the operator limits its scope. Continue through validation, signing, notarization, promotion, and verification without asking for separate macOS consent. Keep the exact release identity and all artifact checks. macOS publication runs in parallel with npm and never blocks it; a mac failure does not hold the npm/ClawHub release, GitHub release finalization, or main closeout. Fix it in parallel.
Follow the current owner-configured environment policy. Do not invent an extra reviewer requirement or recreate an obsolete one. If GitHub still enforces an approval, report the actual rule and resolve it through its owner; policy changes require explicit organization-owner direction and verified active admin membership. Never impersonate a reviewer, fabricate approval, or use another signing path to bypass an enforced rule.
$release-private.private_key_p8, key_id, issuer_id.xcrun notarytool submit fails with HTTP status code: 401. Unauthenticated.xcrun notarytool history before setting GitHub secrets.$one-password: all op work inside one persistent tmux session, no secret output.$release-private when available.op whoami; never print token values.OP_BIOMETRIC_UNLOCK_ENABLED=false for the manual op account add --signin path.Target release-ops repo environment: openclaw/releases, env mac-release.
Set only after local notary auth validation:
APP_STORE_CONNECT_API_KEY_P8APP_STORE_CONNECT_KEY_IDAPP_STORE_CONNECT_ISSUER_IDDo not update these from mixed sources. All three ASC fields must come from the same 1Password item.
openclaw/openclaw is the public product repo. Its GitHub Releases page is
where macOS assets are ultimately attached.openclaw/openclaw macos-release.yml is public handoff validation only.
It never signs, notarizes, or uploads macOS assets, regardless of
preflight_only.openclaw/releases is the restricted release-ops repo. Its macOS workflows
sign, notarize, validate, and promote assets onto the
openclaw/openclaw GitHub release.source_ref=release/YYYY.M.PATCH for release-ops mac preflight/validation when building that branch variation.tag=vYYYY.M.PATCH pointing at the original stable release commit.mac-release environment for
signing and promotion secrets and its main-only deployment policy. The
authorized release operator continues under that environment's current rules.source_ref; promotion rejects mismatched proof.scripts/notarize-mac-artifact.sh.xcrun notarytool submit should use --no-s3-acceleration; accelerated upload can surface misleading 401s even when notarytool history succeeds.The public handoff workflow validates the tag, source, build, and package metadata before publication. It does not require a GitHub release page because it does not upload assets. Keep this validation before the real publish workflow. The core publisher owns GitHub release finalization; macOS promotion attaches its verified assets to that release whether it is still a draft or already public, so it never waits for the npm flip.
Public handoff validation:
gh workflow run macos-release.yml --repo openclaw/openclaw \
--ref release/YYYY.M.PATCH \
-f tag=vYYYY.M.PATCH \
-f preflight_only=true \
-f public_release_branch=release/YYYY.M.PATCH
release/YYYY.M.PATCH, matching prior stable macOS handoff runs.--ref main or --ref vYYYY.M.PATCH for this public handoff
validation. The workflow checks out the tag from the tag input internally.Release-ops preflight:
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f source_ref=release/YYYY.M.PATCH \
-f preflight_only=true \
-f smoke_test_only=false \
-f allow_late_calver_recovery=false \
-f public_release_branch=release/YYYY.M.PATCH
Follow the run through signing and notarization under the configured environment policy. Record the successful preflight run id; an approval pause is not a successful preflight.
Resume is the default. Re-dispatching the same preflight command after a
failure (notary outage, DMG packaging, collector) resumes every variant from
the newest checkpoint left by a failed or cancelled main dispatch for the same
tag and source SHA; only variants without a checkpoint rebuild. The run log
prints Resuming <variant> from run <id> attempt <n> or Building <variant>.
ignore_checkpoints=true forces fresh builds. Pass resume_notarization_run_id,
resume_notarization_run_attempt, and resume_notarization_variant only to pin
one specific run, or for checkpoints made before the resume index existed
(macos-resume-<tag>-<variant>-<sha> artifacts). Prefer
gh run rerun <run-id> --failed --repo openclaw/releases when the failed job is
still in the current run.
Release-ops validation for a branch-variation preflight:
gh workflow run openclaw-macos-validate.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f source_ref=release/YYYY.M.PATCH
Record the successful validation run id.
Real publish:
gh workflow run openclaw-macos-publish.yml --repo openclaw/releases --ref main \
-f tag=vYYYY.M.PATCH \
-f preflight_only=false \
-f smoke_test_only=false \
-f preflight_run_id=<successful-preflight-run> \
-f validate_run_id=<successful-validation-run> \
-f allow_late_calver_recovery=false \
-f public_release_branch=release/YYYY.M.PATCH
Follow promotion through asset upload and appcast publication under the same release authorization and current environment policy.
openclaw/releases publish/validate workflows run from their own
trusted main workflow ref. Real publish has a guard that rejects any other
workflow ref. That displayed main ref is expected; the public OpenClaw
source is selected by tag and optional source_ref.gh release view vYYYY.M.PATCH --repo openclaw/openclaw shows zip, dmg, dSYM zip; once the npm publisher has flipped it: not draft, not prerelease.main appcast.xml points at OpenClaw-YYYY.M.PATCH.zip.sparkle:version, sparkle:shortVersionString, length, and sparkle:edSignature.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
OpenClawへの自然な言葉の依頼をClaude Codeなどの外部コーディングエージェントへ振り分け、作業の開始や継続、スレッド内の会話をつなぐスキルです。
Add and live-prove a model provider with non-interactive config one-liners, without exposing credentials.
日本語の概要は準備中です。原文の説明を表示しています。
Requested GitHub PR/issue agent transcripts: redact, trim, preview, and insert safely.
日本語の概要は準備中です。原文の説明を表示しています。
macOSのApple Notesをエージェントから作成・検索・編集・削除し、フォルダ間の移動やHTML・Markdownへの書き出しを行うスキル。
Apple Remindersの予定付きToDoをMacから確認・追加・編集するスキル。リストの管理や完了・削除にも対応し、iPhoneやiPadで見るタスクを整理できます。