Skip to content

Commit 688229c

Browse files
committed
Notarize app bundle on macOS
1 parent 53955c4 commit 688229c

1 file changed

Lines changed: 56 additions & 0 deletions

File tree

‎.github/workflows/macos.yml‎

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,62 @@ jobs:
3232
- name: Bundle
3333
run: cargo cntp-bundle --target x86_64-apple-darwin --target aarch64-apple-darwin
3434
working-directory: thegrid
35+
# Codesigning adapted from https://federicoterzi.com/blog/automatic-code-signing-and-notarization-for-macos-apps-using-github-actions/
36+
- name: Codesign app bundle
37+
env:
38+
MACOS_CERTIFICATE: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE }}
39+
MACOS_CERTIFICATE_PWD: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
40+
MACOS_CERTIFICATE_NAME: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_NAME }}
41+
MACOS_CI_KEYCHAIN_PWD: ${{ secrets.APPLE_DEVELOPER_KEYCHAIN_PASSWORD }}
42+
run: |
43+
# Turn our base64-encoded certificate back to a regular .p12 file
44+
45+
echo $MACOS_CERTIFICATE | base64 --decode > certificate.p12
46+
47+
# We need to create a new keychain, otherwise using the certificate will prompt
48+
# with a UI dialog asking for the certificate password, which we can't
49+
# use in a headless CI environment
50+
51+
security create-keychain -p "$MACOS_CI_KEYCHAIN_PWD" build.keychain
52+
security default-keychain -s build.keychain
53+
security unlock-keychain -p "$MACOS_CI_KEYCHAIN_PWD" build.keychain
54+
security import certificate.p12 -k build.keychain -P "$MACOS_CERTIFICATE_PWD" -T /usr/bin/codesign
55+
security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$MACOS_CI_KEYCHAIN_PWD" build.keychain
56+
57+
# We finally codesign our app bundle, specifying the Hardened runtime option
58+
59+
/usr/bin/codesign --force -s "$MACOS_CERTIFICATE_NAME" --options runtime target/bundle/*/release/*.app -v
60+
- name: "Notarize app bundle"
61+
env:
62+
PROD_MACOS_NOTARIZATION_APPLE_ID: ${{ secrets.APPLE_NOTARIZATION_APPLE_ID }}
63+
PROD_MACOS_NOTARIZATION_TEAM_ID: ${{ secrets.APPLE_NOTARIZATION_TEAM_ID }}
64+
PROD_MACOS_NOTARIZATION_PWD: ${{ secrets.APPLE_NOTARIZATION_PASSWORD }}
65+
run: |
66+
# Store the notarization credentials so that we can prevent a UI password dialog
67+
# from blocking the CI
68+
69+
echo "Create keychain profile"
70+
xcrun notarytool store-credentials "notarytool-profile" --apple-id "$PROD_MACOS_NOTARIZATION_APPLE_ID" --team-id "$PROD_MACOS_NOTARIZATION_TEAM_ID" --password "$PROD_MACOS_NOTARIZATION_PWD"
71+
72+
# We can't notarize an app bundle directly, but we need to compress it as an archive.
73+
# Therefore, we create a zip file containing our app bundle, so that we can send it to the
74+
# notarization service
75+
76+
echo "Creating temp notarization archive"
77+
ditto -c -k --keepParent "target/bundle/*/release/*.app" "notarization.zip"
78+
79+
# Here we send the notarization request to the Apple's Notarization service, waiting for the result.
80+
# This typically takes a few seconds inside a CI environment, but it might take more depending on the App
81+
# characteristics. Visit the Notarization docs for more information and strategies on how to optimize it if
82+
# you're curious
83+
84+
echo "Notarize app"
85+
xcrun notarytool submit "notarization.zip" --keychain-profile "notarytool-profile" --wait
86+
87+
# Finally, we need to "attach the staple" to our executable, which will allow our app to be
88+
# validated by macOS even when an internet connection is not available.
89+
echo "Attach staple"
90+
xcrun stapler staple "target/bundle/*/release/*.app"
3591
- name: Deploy
3692
run: cargo cntp-deploy --target x86_64-apple-darwin --target aarch64-apple-darwin --output-file "$HOME/theGrid-macOS.dmg"
3793
working-directory: thegrid

0 commit comments

Comments
 (0)