feat(release): build and publish macOS from the Mac, not CI - #122
Merged
Merged
Conversation
The Developer ID certificate and the notarytool keychain profile live only in the release Mac's keychain, so a CI runner can only produce an unsigned mac build — and the app now updates itself through Squirrel.Mac, which refuses an update not signed by the same Developer ID. macOS is released locally: npm run release patch # tag → release.yml + Windows/Linux in CI (unchanged) npm run release:mac # this Mac: build, verify, upload, bump the cask scripts/release-mac.js: - preflight: HEAD is the tag, tree clean, origin's tag = HEAD; the notarytool profile works; the GitHub Release exists and is not a draft. - electron-builder --mac --publish NEVER: it skips notarization silently when the profile is missing, so --publish always would ship that build. - verify before upload: codesign; spctl (exit 0 + "Notarized Developer ID") on the app and on the app inside the mounted dmg, both at the tag's version; stapler; latest-mac.yml names this zip and carries the real sha512 of the zip and dmg. - gh release upload; existing mac assets only with --force; a part-way failure says what is and is not on the release. - transitional cask bump with the dmg's sha256 only once it equals the digest GitHub serves; --cask-only redoes that step. release-desktop.yml builds Windows/Linux only; the MAC_*/APPLE_* secrets and bump-cask are gone (HOMEBREW_TAP_TOKEN is now unused). Reviewed by codex; its findings are fixed and pinned. Verified on the notarized 7.17.0 build: the verification step passes, --cask-only refuses a dmg that is not the release's. Tests: test/release-mac.test.js (38 checks, each guard mutation-checked); test/mac-signing.test.js now pins that CI does not build macOS. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
macOS needs the Developer ID certificate and the notarytool profile, which exist only in the release Mac's keychain; a CI runner can only make an unsigned build, and Squirrel.Mac refuses unsigned updates. So:
npm run releaseas before (Windows/Linux in CI), thennpm run release:macon the Mac — build with--publish never, verify notarization of the app and the app inside the dmg plus latest-mac.yml checksums, then upload and bump the transitional cask. Seedocs/electron-desktop/MAC-SIGNING.md. Tests:release-mac.test.js(38),mac-signing.test.js(CI builds no macOS).