Skip to content

Sign releases with Developer ID and notarize them - #3

Merged
aodjo merged 1 commit into
mainfrom
release/notarized
Sep 12, 2026
Merged

aodjo merged 1 commit into
mainfrom
release/notarized

Conversation

@aodjo

@aodjo aodjo commented Sep 12, 2026

Copy link
Copy Markdown
Owner

Releases so far were ad-hoc signed and not notarized, so Gatekeeper blocked the first launch and users had to click "Open Anyway". This PR matches Reprise: Developer ID signing, hardened runtime, notarization and stapling.

  • scripts/build-app.sh: a Developer ID identity (or HARDENED_RUNTIME=1) adds --options runtime --timestamp.
  • scripts/release.sh vX.Y.Z:
    • Tags main's HEAD and builds a universal app.
    • Signs it with the Developer ID Application identity.
    • Notarizes it with notarytool using a keychain profile (macTree by default), then staples the ticket and checks it with spctl.
    • Publishes the release with MacTree-vX.Y.Z.zip and prints the SHA-256 for the Homebrew cask.
    • Stops before touching git if the notary profile or the identity is missing.
  • build.yml: drops the release job. The signing key stays on the Mac rather than in CI secrets, so CI only builds and tests.

Tested locally:

  • Developer ID signature with flags=0x10000(runtime) and a secure timestamp on the universal binary.
  • A scan and the Full Disk Access probe both run under the hardened runtime.
  • spctl reports "Unnotarized Developer ID" until notarization, as expected.
  • release.sh exits early without creating a tag when the profile is missing.

https://claude.ai/code/session_0115d7b3mfRT6Gs8mgqtAt1x

build-app.sh enables the hardened runtime and a secure timestamp for
Developer ID identities. scripts/release.sh builds a universal app, signs
it, notarizes and staples it, and publishes the GitHub release with the
zip. The signing key stays on the Mac instead of in CI secrets, so CI now
only builds and tests.

Claude-Session: https://claude.ai/code/session_0115d7b3mfRT6Gs8mgqtAt1x
Copilot AI lite review requested due to automatic review settings September 12, 2026 10:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@aodjo
aodjo merged commit 44f112c into main Sep 12, 2026
1 check passed
@aodjo
aodjo deleted the release/notarized branch September 12, 2026 10:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants