Skip to content

feat: Add macOS code signing and notarization #3

feat: Add macOS code signing and notarization

feat: Add macOS code signing and notarization #3

Workflow file for this run

name: macOS signing
on:
pull_request:
branches: [main]
paths:
- scripts/sign-macos.sh
- .github/macos/entitlements.plist
- .github/workflows/macos-signing.yml
push:
branches: [main]
paths:
- scripts/sign-macos.sh
- .github/macos/entitlements.plist
- .github/workflows/macos-signing.yml
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
sign-macos:
# Fork PRs cannot access the Apple credentials. Test them on a repository branch.
if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository
runs-on: macos-latest
timeout-minutes: 45
steps:
- uses: actions/checkout@v7
- uses: ./.github/actions/install-frontend-dependencies
- name: Set up cargo cache
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4
env:
NODE_OPTIONS: --no-deprecation
- name: Run the signing helper
env:
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
APPLE_NOTARIZATION_APPLE_ID: ${{ secrets.APPLE_NOTARIZATION_APPLE_ID }}
APPLE_NOTARIZATION_PASSWORD: ${{ secrets.APPLE_NOTARIZATION_PASSWORD }}
APPLE_NOTARIZATION_TEAM_ID: ${{ secrets.APPLE_NOTARIZATION_TEAM_ID }}
P12_BASE64: ${{ secrets.APPLE_SIGNING_CERTIFICATE_P12_BASE64 }}
P12_PASSWORD: ${{ secrets.APPLE_SIGNING_CERTIFICATE_PASSWORD }}
run: |
set -euo pipefail
: "${APPLE_SIGNING_IDENTITY:?Missing APPLE_SIGNING_IDENTITY secret}"
: "${APPLE_NOTARIZATION_APPLE_ID:?Missing APPLE_NOTARIZATION_APPLE_ID secret}"
: "${APPLE_NOTARIZATION_PASSWORD:?Missing APPLE_NOTARIZATION_PASSWORD secret}"
: "${APPLE_NOTARIZATION_TEAM_ID:?Missing APPLE_NOTARIZATION_TEAM_ID secret}"
: "${P12_BASE64:?Missing APPLE_SIGNING_CERTIFICATE_P12_BASE64 secret}"
: "${P12_PASSWORD:?Missing APPLE_SIGNING_CERTIFICATE_PASSWORD secret}"
CERTIFICATE_PATH="$RUNNER_TEMP/signing.p12"
KEYCHAIN_PATH="$RUNNER_TEMP/signing.keychain-db"
trap 'security delete-keychain "$KEYCHAIN_PATH"; rm -f "$CERTIFICATE_PATH"' EXIT
# Use PKCS12 algorithms supported by macOS Keychain.
printf '%s' "$P12_BASE64" | base64 -d |
openssl pkcs12 -passin env:P12_PASSWORD -nodes |
openssl pkcs12 -export -passout env:P12_PASSWORD \
-keypbe PBE-SHA1-3DES -certpbe PBE-SHA1-3DES -macalg sha1 -out "$CERTIFICATE_PATH"
security create-keychain -p "" "$KEYCHAIN_PATH"
security set-keychain-settings -lut 3600 "$KEYCHAIN_PATH"
security unlock-keychain -p "" "$KEYCHAIN_PATH"
security import "$CERTIFICATE_PATH" -k "$KEYCHAIN_PATH" -P "$P12_PASSWORD" -T /usr/bin/codesign
security set-key-partition-list -S apple-tool:,apple: -s -k "" "$KEYCHAIN_PATH" > /dev/null
security list-keychains -d user -s "$KEYCHAIN_PATH"
scripts/sign-macos.sh
- name: Run the signed binary
run: target/aarch64-apple-darwin/superoptimized/sqlpage --version