Repository navigation
Sign releases with a Developer ID and notarise them - #5
Merged
Merged
Conversation
The release job builds the DMG itself with the Developer ID identity from repository secrets, notarises and staples it. The cask no longer strips the quarantine attribute, and manual installs no longer need xattr. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YXLtjqcyvZ1VP9uK9jnMuR
The pinned Swift 6.1 toolchain cannot build against the macOS 26.5 SDK in the runner's Xcode, so every build failed at the first import. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YXLtjqcyvZ1VP9uK9jnMuR
CI moves to the xcode-27 runner image, since macos-latest defaults to Xcode 26.6. The manifest requires Swift tools 6.4, and the checkout, upload-artifact and action-gh-release pins move to their current majors. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YXLtjqcyvZ1VP9uK9jnMuR
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release DMGs were ad-hoc signed, so Gatekeeper refused them and the cask ran
xattr -crin a postflight step (and manual installs had to do it by hand). This signs and notarises releases so neither is needed.What changes
create-app-bundlesigns withSIGN_IDENTITYwhen set: hardened runtime, secure timestamp, and the bundledbrowser-schedule-clisigned before the bundle (no--deep, which Apple advises against for distribution signing). Unset, it ad-hoc signs as before, sotask installand PR builds are unchanged.New
task notarizesigns the DMG, submits it withnotarytoolusing an App Store Connect API key, staples and validates the ticket, and checks it withspctl.Release job no longer reuses the
buildjob's ad-hoc DMG. When a version bump triggers a release, it imports the Developer ID certificate into a per-job keychain with a random password, builds the DMG signed, and notarises it. PR builds and non-release pushes never touch the secrets or the notary service.Cask drops the
postflight_stepsxattr block; release notes drop the manualxattrstep.Toolchain: CI runs on the
xcode-27runner image (Xcode 27.0, Swift 6.4) with Xcode's bundled Swift, replacingswift-actions/setup-swift. Its pinned Swift 6.1 could not build against the SDK in the runner's Xcode, which has failed every build onmain.macos-lateststill defaults to Xcode 26.6, so it would leave the build a major version behind.Package.swiftmoves toswift-tools-version: 6.4; dependencies were already at their latest compatible versions.Action pins:
actions/checkoutv7.0.1,actions/upload-artifactv7.0.1,softprops/action-gh-releasev3.0.3, matching koan.Risk
If the secrets are missing, the release job fails at the certificate import rather than shipping an ad-hoc build. That is deliberate: the regenerated cask no longer strips quarantine, so an unsigned release published through it would be blocked by Gatekeeper for every Homebrew user. Nothing runs until
VERSIONis bumped.xcode-27is a GitHub preview image. If it becomes unavailable,macos-26plussudo xcode-select -s /Applications/Xcode_26.6.appis the fallback, along with dropping the manifest to tools 6.3.Required before the next release
Repository secrets on this repo (same names and encoding as koan's):
MACOS_CERTIFICATE_P12: base64 of the Developer ID Application.p12MACOS_CERTIFICATE_PASSWORDAPPLE_API_KEY_P8: base64 of the App Store Connect.p8APPLE_API_KEY_ID,APPLE_API_ISSUER_IDVerifying
Locally, both signing paths of
create-app-bundleproduce a bundle that passescodesign --verify --strict --deep; with an identity, both binaries carry theruntimeflag and a timestamp, and the hardened CLI runs. The notarisation step itself is only exercised by the first release after merge; watch theNotarisestep'snotarytoollog.🤖 Generated with Claude Code
https://claude.ai/code/session_01YXLtjqcyvZ1VP9uK9jnMuR