Skip to content

feat(release): build and publish macOS from the Mac, not CI - #122

Merged
Lexus2016 merged 1 commit into
mainfrom
feat/local-mac-release
Sep 28, 2026
Merged

Lexus2016 merged 1 commit into
mainfrom
feat/local-mac-release

Conversation

@Lexus2016

Copy link
Copy Markdown
Owner

macOS needs the Developer ID certificate and the notarytool profile, which exist only in the release Mac's keychain; a CI runner can only make an unsigned build, and Squirrel.Mac refuses unsigned updates. So: npm run release as before (Windows/Linux in CI), then npm run release:mac on the Mac — build with --publish never, verify notarization of the app and the app inside the dmg plus latest-mac.yml checksums, then upload and bump the transitional cask. See docs/electron-desktop/MAC-SIGNING.md. Tests: release-mac.test.js (38), mac-signing.test.js (CI builds no macOS).

The Developer ID certificate and the notarytool keychain profile live only in
the release Mac's keychain, so a CI runner can only produce an unsigned mac
build — and the app now updates itself through Squirrel.Mac, which refuses an
update not signed by the same Developer ID. macOS is released locally:

  npm run release patch   # tag → release.yml + Windows/Linux in CI (unchanged)
  npm run release:mac     # this Mac: build, verify, upload, bump the cask

scripts/release-mac.js:
- preflight: HEAD is the tag, tree clean, origin's tag = HEAD; the notarytool
  profile works; the GitHub Release exists and is not a draft.
- electron-builder --mac --publish NEVER: it skips notarization silently when
  the profile is missing, so --publish always would ship that build.
- verify before upload: codesign; spctl (exit 0 + "Notarized Developer ID")
  on the app and on the app inside the mounted dmg, both at the tag's version;
  stapler; latest-mac.yml names this zip and carries the real sha512 of the
  zip and dmg.
- gh release upload; existing mac assets only with --force; a part-way failure
  says what is and is not on the release.
- transitional cask bump with the dmg's sha256 only once it equals the digest
  GitHub serves; --cask-only redoes that step.

release-desktop.yml builds Windows/Linux only; the MAC_*/APPLE_* secrets and
bump-cask are gone (HOMEBREW_TAP_TOKEN is now unused). Reviewed by codex; its
findings are fixed and pinned. Verified on the notarized 7.17.0 build: the
verification step passes, --cask-only refuses a dmg that is not the release's.

Tests: test/release-mac.test.js (38 checks, each guard mutation-checked);
test/mac-signing.test.js now pins that CI does not build macOS.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@Lexus2016
Lexus2016 merged commit 27414f3 into main Sep 28, 2026
2 checks passed
@Lexus2016
Lexus2016 deleted the feat/local-mac-release branch September 28, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant