# How to Set Up CI/CD for Palmier Pro: Complete GitHub Actions & Release Automation Guide

> Automate macOS builds and signed releases for Palmier Pro with GitHub Actions. This guide covers setting up CI/CD using a simple release script and repository secrets.

- Repository: [Palmier/palmier-pro](https://github.com/palmier-io/palmier-pro)
- Tags: how-to-guide
- Published: 2026-06-23

---

**Palmier Pro ships with a production-ready CI/CD pipeline using GitHub Actions for macOS builds and a [`scripts/release.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/release.sh) automation script for signed releases, requiring only a macOS runner and standard repository secrets to deploy.**

Setting up CI/CD for Palmier Pro requires minimal configuration because the AI-native macOS video editor includes pre-configured automation. The repository provides a complete continuous integration workflow that builds and tests on every push, plus a deterministic release script that manages the entire delivery pipeline from version bump to GitHub Release publication.

## Continuous Integration (CI) Configuration

The CI pipeline is defined in **[`.github/workflows/ci.yml`](https://github.com/palmier-io/palmier-pro/blob/main/.github/workflows/ci.yml)** and executes on every push to `main` and every pull request.

### macOS Runner and Toolchain Setup

The workflow targets the macOS platform specifically using `runs-on: macos-26`, ensuring builds execute on **macOS 26 (Tahoe)** to match the app's deployment target. The configuration begins by verifying the Swift toolchain with `swift --version`, creating an auditable build environment that prints the exact compiler version to logs.

### Swift Package Manager Caching Strategy

**Swift Package Manager** dependencies are cached using `actions/cache@v4` with the path set to `.build` and cache keys derived from **`Package.resolved`**. This significantly accelerates incremental builds by preserving compiled dependencies between runs. The pipeline then executes `swift build` to compile the project and `swift test` to run the test suite located in `Tests/PalmierProTests/`, ensuring all changes remain regression-free.

```yaml

# .github/workflows/ci.yml

name: CI

on:
  push:
    branches: [main]
  pull_request:

jobs:
  build-test:
    runs-on: macos-26
    steps:
      - uses: actions/checkout@v4
      - name: Show toolchain
        run: swift --version
      - name: Cache SwiftPM
        uses: actions/cache@v4
        with:
          path: .build
          key: spm-${{ runner.os }}-${{ hashFiles('Package.resolved') }}
      - name: Build
        run: swift build
      - name: Test
        run: swift test

```

## Continuous Delivery (CD) Automation

While CI validates code quality, the CD process is orchestrated by **[`scripts/release.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/release.sh)**, a deterministic automation script that requires only a version argument to execute the full release pipeline.

### The Release Script Pipeline

Running `./scripts/release.sh 0.2.0` performs seven critical operations:

1. **Pre-flight validation** – Confirms clean working tree, correct branch state, and tag uniqueness.
2. **Version bumping** – Updates `CFBundleShortVersionString` and auto-increments `CFBundleVersion` in the bundle property list.
3. **Release notes generation** – Creates a Markdown file containing commit messages since the last tag.
4. **Binary packaging** – Invokes `scripts/bundle.sh release --dist` to produce a signed and notarized DMG.
5. **Git operations** – Commits version changes, pushes to origin, creates a Git tag, and pushes the tag.
6. **GitHub Release creation** – Uses `gh release create` to publish the DMG with generated notes.
7. **Appcast update** – Inserts a new `<item>` entry into [`appcast.xml`](https://github.com/palmier-io/palmier-pro/blob/main/appcast.xml) following the **Sparkle** update feed specification for in-app auto-updates.

### Version Management and Configuration Files

The release script modifies **`Sources/PalmierPro/Resources/Info.plist`** directly, reading and updating the `CFBundleShortVersionString` and `CFBundleVersion` keys. The script also updates **[`appcast.xml`](https://github.com/palmier-io/palmier-pro/blob/main/appcast.xml)** to include the new version entry, ensuring the in-app update checker can discover releases immediately after publication.

```bash

# Execute full release pipeline

./scripts/release.sh 0.2.0

```

## Integrating CI with CD

A complete CI/CD setup connects automated testing with release deployment. Configure your repository to run the CI workflow on every push and pull request, then trigger [`scripts/release.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/release.sh) manually or via a workflow dispatch job after successful CI completion on the protected `main` branch.

Because the workflow runs on `macos-26`, no cross-compilation or Docker containers are required. The release script requires only standard repository secrets including `GITHUB_TOKEN` for GitHub CLI authentication.

## Configuration Requirements and Best Practices

To ensure the pipeline functions correctly:

- Commit **`Package.resolved`** to version control; the CI cache key in [`.github/workflows/ci.yml`](https://github.com/palmier-io/palmier-pro/blob/main/.github/workflows/ci.yml) depends on this file for dependency management.
- Maintain the **`Info.plist`** path at `Sources/PalmierPro/Resources/Info.plist`; the release script reads and modifies this file directly using plist manipulation tools.
- Preserve the **[`appcast.xml`](https://github.com/palmier-io/palmier-pro/blob/main/appcast.xml)** structure as Sparkle-compatible XML; custom modifications must maintain the `<item>` insertion logic used by the release script to prevent breaking automatic updates.

## Summary

- Palmier Pro provides a complete CI/CD setup via [`.github/workflows/ci.yml`](https://github.com/palmier-io/palmier-pro/blob/main/.github/workflows/ci.yml) and [`scripts/release.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/release.sh) with zero additional configuration required.
- The CI pipeline uses `macos-26` runners with `actions/cache@v4` for SwiftPM caching and executes `swift build` and `swift test` on every pull request.
- The release script automates versioning in `Info.plist`, DMG creation via [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh), Git tagging, GitHub Releases, and Sparkle [`appcast.xml`](https://github.com/palmier-io/palmier-pro/blob/main/appcast.xml) updates.
- macOS-specific builds require no cross-platform tooling; the entire workflow runs natively on GitHub-hosted macOS runners.

## Frequently Asked Questions

### How do I trigger a new release for Palmier Pro?

Execute `./scripts/release.sh <version>` (for example, `./scripts/release.sh 0.2.0`) from the repository root. The script performs pre-flight checks, updates version strings in `Sources/PalmierPro/Resources/Info.plist`, builds a signed DMG via [`scripts/bundle.sh`](https://github.com/palmier-io/palmier-pro/blob/main/scripts/bundle.sh), creates a Git tag, publishes a GitHub Release using `gh release create`, and updates [`appcast.xml`](https://github.com/palmier-io/palmier-pro/blob/main/appcast.xml) for Sparkle updates.

### What macOS version does the CI use?

The workflow specifies `runs-on: macos-26`, utilizing macOS 26 (Tahoe) runners to ensure builds match the target deployment environment. This eliminates cross-compilation issues and ensures native macOS framework compatibility for the video editor.

### Where does the release script update version numbers?

The script modifies `Sources/PalmierPro/Resources/Info.plist`, specifically updating `CFBundleShortVersionString` with the provided semantic version and auto-incrementing `CFBundleVersion` for build identification. Ensure this path remains unchanged in your project structure.

### Can I run the release script from GitHub Actions?

Yes, the release script is designed to run within CI environments. Configure a workflow job that checks out the repository on a `macos-26` runner, provides the necessary secrets (including `GITHUB_TOKEN` for GitHub CLI access), and executes [`./scripts/release.sh`](https://github.com/palmier-io/palmier-pro/blob/main/./scripts/release.sh) with the desired version parameter to fully automate releases.