π€ Add macOS notarization support #90
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
@spikecurtis - Secrets Added β
Spike has configured the App Store Connect API key secrets. This PR is ready to merge and test!
Problem
Current state:
When users download the DMG, macOS shows:
The app is properly signed, but requires notarization to pass Gatekeeper on modern macOS.
Solution
This PR adds notarization support using App Store Connect API keys (more secure than app-specific passwords):
Changes
1. Workflow updates (
.github/workflows/build.yml):API_KEY_ID,API_KEY_ISSUER_ID,API_KEYenvironment variables2. electron-builder config (
package.json):notarizeblock with team ID (4399GN35BJ)How it works
After merge
Once this merges:
Current build status
Latest main build (run #18325710712):
codesign --verify --deep --strictspctl -a -vvshows "Unnotarized Developer ID"Testing
After merge:
spctl -a -vv Cmux.appshould show "accepted" (not "rejected")Generated with
cmux