chore: sign and notarize macOS release binaries (#32946)

This commit is contained in:
Michael Geers 2026-08-18 12:35:22 +02:00 • committed by GitHub
parent f4b289f745
commit 88b641301a
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 19 additions and 7 deletions

View file

@ -144,6 +144,12 @@ jobs:
# a bugfix release of an older line must not move the homebrew formula # a bugfix release of an older line must not move the homebrew formula
# or the Github latest release marker # or the Github latest release marker
MAKE_LATEST: ${{ needs.guard.outputs.latest }} MAKE_LATEST: ${{ needs.guard.outputs.latest }}
# macOS code signing and notarization
MACOS_SIGN_P12: ${{ secrets.MACOS_SIGN_P12 }}
MACOS_SIGN_PASSWORD: ${{ secrets.MACOS_SIGN_PASSWORD }}
MACOS_NOTARY_KEY: ${{ secrets.MACOS_NOTARY_KEY }}
MACOS_NOTARY_KEY_ID: ${{ secrets.MACOS_NOTARY_KEY_ID }}
MACOS_NOTARY_ISSUER_ID: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
- uses: actions/setup-python@v6 - uses: actions/setup-python@v6
with: with:

View file

@ -60,6 +60,19 @@ archives:
universal_binaries: universal_binaries:
- replace: true - replace: true
notarize:
macos:
- enabled: '{{ isEnvSet "MACOS_SIGN_P12" }}'
sign:
certificate: "{{ .Env.MACOS_SIGN_P12 }}"
password: "{{ .Env.MACOS_SIGN_PASSWORD }}"
notarize:
issuer_id: "{{ .Env.MACOS_NOTARY_ISSUER_ID }}"
key_id: "{{ .Env.MACOS_NOTARY_KEY_ID }}"
key: "{{ .Env.MACOS_NOTARY_KEY }}"
wait: true
timeout: 20m
checksum: checksum:
name_template: "checksums.txt" name_template: "checksums.txt"
@ -136,10 +149,3 @@ homebrew_casks:
description: "Sonne tanken ☀️🚘" description: "Sonne tanken ☀️🚘"
binaries: binaries:
- evcc - evcc
hooks:
post:
# the binaries are not notarized, so gatekeeper would refuse to run them
install: |
if OS.mac?
system_command "/usr/bin/xattr", args: ["-dr", "com.apple.quarantine", "#{staged_path}/evcc"]
end