Signed, notarized releases on version tags - #8
Merged
Merged
Conversation
Distributed builds need a Developer ID signature with the hardened runtime and a secure timestamp to pass notarization, and a universal binary so the app runs on Intel Macs, which macOS 15+ still supports. SIGN_IDENTITY, UNIVERSAL, and VERSION are optional; the defaults keep the existing ad-hoc build for people compiling from source. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pushing a v* tag builds a universal app signed with the Developer ID certificate, notarizes and staples it with scripts/notarize.sh, and attaches MacDirStat.zip to a GitHub Release. The asset name stays fixed so releases/latest/download/MacDirStat.zip is a stable download link. The certificate has no CA Issuers URL, so the workflow imports Apple's Developer ID intermediates itself. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
scripts/build-app.shtakes optionalSIGN_IDENTITY,UNIVERSAL=1, andVERSION. With a Developer ID identity it signs with the hardened runtime and a secure timestamp, as notarization requires. The defaults keep the ad-hoc build for people compiling from source.scripts/notarize.shsubmits the app withnotarytoolusing an App Store Connect API key, prints Apple's log if it's rejected, then staples the ticket and zips the app..github/workflows/release.yml: pushing av*tag builds a universal app, signs it with the Developer ID cert from repo secrets, notarizes it, and publishesMacDirStat.zipas a GitHub Release. The asset name stays fixed, soreleases/latest/download/MacDirStat.zipis a stable download link for the README.The repo secrets (
DEVELOPER_ID_P12_BASE64,DEVELOPER_ID_P12_PASSWORD,NOTARY_API_KEY,NOTARY_KEY_ID,NOTARY_ISSUER_ID) are already set.Testing
Run locally on macOS 27:
SIGN_IDENTITY=<Developer ID> UNIVERSAL=1 ./scripts/build-app.sh: the signature verifies (Developer ID, G2 intermediate, hardened runtime, timestamp), the binary is arm64 + x86_64 withminos 15.0, and the app launches../scripts/notarize.sh: Apple accepted the build and the ticket stapled. A copy unzipped from the output and marked as downloaded passes Gatekeeper (spctl:accepted, source=Notarized Developer ID)..p12in a throwaway keychain (base64 round trip, import, partition list, timestamped signature).Not tested yet: the workflow itself. It only runs on a tag, so the first real run will be the
v0.1.0tag after merge.🤖 Generated with Claude Code