diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 09c2fd088..914b468be 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -144,6 +144,12 @@ jobs: # a bugfix release of an older line must not move the homebrew formula # or the Github latest release marker MAKE_LATEST: ${{ needs.guard.outputs.latest }} + # macOS code signing and notarization + MACOS_SIGN_P12: ${{ secrets.MACOS_SIGN_P12 }} + MACOS_SIGN_PASSWORD: ${{ secrets.MACOS_SIGN_PASSWORD }} + MACOS_NOTARY_KEY: ${{ secrets.MACOS_NOTARY_KEY }} + MACOS_NOTARY_KEY_ID: ${{ secrets.MACOS_NOTARY_KEY_ID }} + MACOS_NOTARY_ISSUER_ID: ${{ secrets.MACOS_NOTARY_ISSUER_ID }} - uses: actions/setup-python@v6 with: diff --git a/.goreleaser.yml b/.goreleaser.yml index ff4d59c91..8c1d08ea3 100644 --- a/.goreleaser.yml +++ b/.goreleaser.yml @@ -60,6 +60,19 @@ archives: universal_binaries: - replace: true +notarize: + macos: + - enabled: '{{ isEnvSet "MACOS_SIGN_P12" }}' + sign: + certificate: "{{ .Env.MACOS_SIGN_P12 }}" + password: "{{ .Env.MACOS_SIGN_PASSWORD }}" + notarize: + issuer_id: "{{ .Env.MACOS_NOTARY_ISSUER_ID }}" + key_id: "{{ .Env.MACOS_NOTARY_KEY_ID }}" + key: "{{ .Env.MACOS_NOTARY_KEY }}" + wait: true + timeout: 20m + checksum: name_template: "checksums.txt" @@ -136,10 +149,3 @@ homebrew_casks: description: "Sonne tanken ☀️🚘" binaries: - evcc - hooks: - post: - # the binaries are not notarized, so gatekeeper would refuse to run them - install: | - if OS.mac? - system_command "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "#{staged_path}/evcc"] - end