Repository navigation
Add a release process with signing and notarization - #79
Merged
Merged
Conversation
oNaiPs
force-pushed
the
worktree-release-flow
branch
from
September 28, 2026 13:42
2e66a66 to
ad93447
Compare
oNaiPs
added a commit
that referenced
this pull request
Sep 28, 2026
Releases were cut by hand: the version was hardcoded in Info.plist, the only automation was a hub call in main.yml that no longer runs, and builds were ad-hoc signed, which is why the Homebrew cask got disabled for failing Gatekeeper (#50). - Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have Info.plist read them. - Enable the hardened runtime and add the Apple Events entitlement that TerminalLauncher needs under it. - Add scripts/release.sh to bump, commit, tag and push a release. - Add a Release workflow that runs on version tags: tests, archives, exports with Developer ID, notarizes, staples and publishes the zip with its sha256 and generated notes. Falls back to an ad-hoc signed pre-release when the signing secrets are missing. workflow_dispatch and pull requests that touch the release files run it as a dry run that uploads the zip as an artifact instead. - Drop the dead hub step from main.yml. - Document the process and the required secrets in RELEASING.md.
oNaiPs
added a commit
that referenced
this pull request
Sep 28, 2026
oNaiPs
added a commit
that referenced
this pull request
Sep 28, 2026
- Keep the signing secrets in a "release" environment that only version tags and main can use, so a pull request run never sees the certificate or the notarization key and takes the ad-hoc path. - Drop the CI token to read-only and pin the SwiftLint action to a commit. - Move to actions/checkout@v7 and actions/upload-artifact@v7; v4 still targets Node.js 20, which the runners warn about.
oNaiPs
force-pushed
the
worktree-release-flow
branch
from
September 28, 2026 15:01
dbf9c73 to
2ef4a0a
Compare
oNaiPs
marked this pull request as ready for review
September 28, 2026 15:01
Releases were cut by hand: the version was hardcoded in Info.plist, the only automation was a hub call in main.yml that no longer runs, and builds were ad-hoc signed, which is why the Homebrew cask got disabled for failing Gatekeeper (#50). - Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have Info.plist read them. - Enable the hardened runtime and add the Apple Events entitlement that TerminalLauncher needs under it. - Add scripts/release.sh to bump, commit, tag and push a release. - Add a Release workflow that runs on version tags: tests, archives, exports with Developer ID, notarizes, staples and publishes the zip with its sha256 and generated notes. Falls back to an ad-hoc signed pre-release when the signing secrets are missing. workflow_dispatch and pull requests that touch the release files run it as a dry run that uploads the zip as an artifact instead. - Drop the dead hub step from main.yml. - Document the process and the required secrets in RELEASING.md.
- Keep the signing secrets in a "release" environment that only version tags and main can use, so a pull request run never sees the certificate or the notarization key and takes the ad-hoc path. - Drop the CI token to read-only and pin the SwiftLint action to a commit. - Move to actions/checkout@v7 and actions/upload-artifact@v7; v4 still targets Node.js 20, which the runners warn about.
oNaiPs
force-pushed
the
worktree-release-flow
branch
from
September 28, 2026 15:02
2ef4a0a to
8a5a865
Compare
oNaiPs
added a commit
that referenced
this pull request
Sep 28, 2026
Releases were cut by hand: the version was hardcoded in Info.plist, the only automation was a hub call in main.yml that no longer runs, and builds were ad-hoc signed, which is why the Homebrew cask got disabled for failing Gatekeeper (#50). - Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have Info.plist read them. - Enable the hardened runtime and add the Apple Events entitlement that TerminalLauncher needs under it. - Add scripts/release.sh to bump, commit, tag and push a release. - Add a Release workflow that runs on version tags: tests, archives, exports with Developer ID, notarizes, staples and publishes the zip with its sha256 and generated notes. Falls back to an ad-hoc signed pre-release when the signing secrets are missing. workflow_dispatch and pull requests that touch the release files run it as a dry run that uploads the zip as an artifact instead. - Drop the dead hub step from main.yml. - Document the process and the required secrets in RELEASING.md.
oNaiPs
added a commit
that referenced
this pull request
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #50. The Homebrew cask was disabled on 2026-09-01 because 0.7.2 is ad-hoc signed and fails Gatekeeper. Until now there was no release process: the version was hardcoded in Info.plist and the only automation was a
hubstep in main.yml that no longer runs on the runners.Release process
MARKETING_VERSION/CURRENT_PROJECT_VERSIONin the pbxproj, read byInfo.plist.TerminalLauncherneeds to script Terminal/iTerm2 under it. Notarization requires the hardened runtime.scripts/release.sh X.Y.Zbumps the version, commitsRelease X.Y.Z, tags and pushes. Refuses to run offmain, with a dirty tree, out of sync with origin, or if the tag exists.notarytool, staples, verifies withspctl, and publishesdmenu-mac.zip+ sha256 as a GitHub release with generated notes. Without the signing secrets it still publishes, but ad-hoc signed and marked pre-release.workflow_dispatchand pull requests that touch the release files run the same pipeline but upload the zip as an artifact instead of publishing.hubstep.RELEASING.mddocuments the process and the secrets.Hardening
releaseenvironment that only version tags andmaincan use, so a PR run never sees them.Verified
spctl→source=Notarized Developer ID.