Skip to content

Signed, notarized releases on version tags - #8

Merged
phalladar merged 2 commits into
mainfrom
release-signing
Oct 3, 2026
Merged

phalladar merged 2 commits into
mainfrom
release-signing

Conversation

@phalladar

Copy link
Copy Markdown
Owner

Summary

  • scripts/build-app.sh takes optional SIGN_IDENTITY, UNIVERSAL=1, and VERSION. With a Developer ID identity it signs with the hardened runtime and a secure timestamp, as notarization requires. The defaults keep the ad-hoc build for people compiling from source.
  • New scripts/notarize.sh submits the app with notarytool using an App Store Connect API key, prints Apple's log if it's rejected, then staples the ticket and zips the app.
  • New .github/workflows/release.yml: pushing a v* tag builds a universal app, signs it with the Developer ID cert from repo secrets, notarizes it, and publishes MacDirStat.zip as a GitHub Release. The asset name stays fixed, so releases/latest/download/MacDirStat.zip is a stable download link for the README.
  • CLAUDE.md documents the release flow and the secrets it needs.

The repo secrets (DEVELOPER_ID_P12_BASE64, DEVELOPER_ID_P12_PASSWORD, NOTARY_API_KEY, NOTARY_KEY_ID, NOTARY_ISSUER_ID) are already set.

Testing

Run locally on macOS 27:

  • SIGN_IDENTITY=<Developer ID> UNIVERSAL=1 ./scripts/build-app.sh: the signature verifies (Developer ID, G2 intermediate, hardened runtime, timestamp), the binary is arm64 + x86_64 with minos 15.0, and the app launches.
  • ./scripts/notarize.sh: Apple accepted the build and the ticket stapled. A copy unzipped from the output and marked as downloaded passes Gatekeeper (spctl: accepted, source=Notarized Developer ID).
  • Ran the workflow's certificate import steps against the secret .p12 in a throwaway keychain (base64 round trip, import, partition list, timestamped signature).
  • The default ad-hoc build still works.

Not tested yet: the workflow itself. It only runs on a tag, so the first real run will be the v0.1.0 tag after merge.

🤖 Generated with Claude Code

phalladar and others added 2 commits October 3, 2026 10:28
Distributed builds need a Developer ID signature with the hardened
runtime and a secure timestamp to pass notarization, and a universal
binary so the app runs on Intel Macs, which macOS 15+ still supports.
SIGN_IDENTITY, UNIVERSAL, and VERSION are optional; the defaults keep the
existing ad-hoc build for people compiling from source.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pushing a v* tag builds a universal app signed with the Developer ID
certificate, notarizes and staples it with scripts/notarize.sh, and
attaches MacDirStat.zip to a GitHub Release. The asset name stays fixed
so releases/latest/download/MacDirStat.zip is a stable download link.

The certificate has no CA Issuers URL, so the workflow imports Apple's
Developer ID intermediates itself.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@phalladar
phalladar merged commit 58513d9 into main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant