Skip to content

First notarized build

Choose a tag to compare

@github-actions github-actions released this 30 Jul 19:39
· 16 commits to main since this release

The first build macOS will actually open. 0.1.0 was unsigned and 0.1.1 was signed but never notarized, so Gatekeeper rejected both. This one is Developer ID signed, notarized and stapled, and ships as a .dmg.

Signing and distribution

  • Notarized and stapled; the disk image is signed and notarized separately, since a staple on the app does not travel inside its container
  • Sparkle's nested helpers (Autoupdate, Updater.app, the XPC services) are re-signed with our Developer ID and a secure timestamp. They previously shipped with Sparkle's own signature, which codesign --verify --deep accepts but notarization rejects
  • Dropped the com.apple.security.get-task-allow debug entitlement that Xcode was injecting
  • /download now resolves through a stable asset name with no GitHub API call, so it can no longer fall back to the releases page when the unauthenticated rate limit is exhausted
  • Release notes now surface Apple's notarization findings on failure instead of dying with an unexplained stapler error

App

  • Proper app icon

Landing

  • Provider table with real per-client MCP config, GitHub-backed changelog, SF-style icons