Skip to content

Add a release process with signing and notarization - #79

Merged
oNaiPs merged 3 commits into
mainfrom
worktree-release-flow
Sep 28, 2026
Merged

oNaiPs merged 3 commits into
mainfrom
worktree-release-flow

Conversation

@oNaiPs

@oNaiPs oNaiPs commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Refs #50. The Homebrew cask was disabled on 2026-09-01 because 0.7.2 is ad-hoc signed and fails Gatekeeper. Until now there was no release process: the version was hardcoded in Info.plist and the only automation was a hub step in main.yml that no longer runs on the runners.

Release process

  • Version lives in the project. MARKETING_VERSION/CURRENT_PROJECT_VERSION in the pbxproj, read by Info.plist.
  • Hardened runtime on, plus the Apple Events entitlement that TerminalLauncher needs to script Terminal/iTerm2 under it. Notarization requires the hardened runtime.
  • scripts/release.sh X.Y.Z bumps the version, commits Release X.Y.Z, tags and pushes. Refuses to run off main, with a dirty tree, out of sync with origin, or if the tag exists.
  • Release workflow on version tags: checks the tag matches the project version, runs the tests, archives, exports with Developer ID (which re-signs with a secure timestamp), notarizes with notarytool, staples, verifies with spctl, and publishes dmenu-mac.zip + sha256 as a GitHub release with generated notes. Without the signing secrets it still publishes, but ad-hoc signed and marked pre-release.
  • Dry runs. workflow_dispatch and pull requests that touch the release files run the same pipeline but upload the zip as an artifact instead of publishing.
  • main.yml loses the dead hub step. RELEASING.md documents the process and the secrets.

Hardening

  • Signing secrets live in a release environment that only version tags and main can use, so a PR run never sees them.
  • CI token is read-only, the SwiftLint action is pinned to a commit, official actions moved to v7 (Node 24).

Verified

  • Locally with the real certificate: Developer ID export, notarization Accepted, staple, spctl → source=Notarized Developer ID.
  • Dry run on this PR (ad-hoc path) green. 212 tests pass.

@oNaiPs
oNaiPs force-pushed the worktree-release-flow branch from 2e66a66 to ad93447 Compare September 28, 2026 13:42
oNaiPs added a commit that referenced this pull request Sep 28, 2026
Releases were cut by hand: the version was hardcoded in Info.plist, the
only automation was a hub call in main.yml that no longer runs, and builds
were ad-hoc signed, which is why the Homebrew cask got disabled for failing
Gatekeeper (#50).

- Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have
  Info.plist read them.
- Enable the hardened runtime and add the Apple Events entitlement that
  TerminalLauncher needs under it.
- Add scripts/release.sh to bump, commit, tag and push a release.
- Add a Release workflow that runs on version tags: tests, archives,
  exports with Developer ID, notarizes, staples and publishes the zip
  with its sha256 and generated notes. Falls back to an ad-hoc signed
  pre-release when the signing secrets are missing. workflow_dispatch and
  pull requests that touch the release files run it as a dry run that
  uploads the zip as an artifact instead.
- Drop the dead hub step from main.yml.
- Document the process and the required secrets in RELEASING.md.
oNaiPs added a commit that referenced this pull request Sep 28, 2026
oNaiPs added a commit that referenced this pull request Sep 28, 2026
- Keep the signing secrets in a "release" environment that only version
  tags and main can use, so a pull request run never sees the certificate
  or the notarization key and takes the ad-hoc path.
- Drop the CI token to read-only and pin the SwiftLint action to a commit.
- Move to actions/checkout@v7 and actions/upload-artifact@v7; v4 still
  targets Node.js 20, which the runners warn about.
@oNaiPs
oNaiPs force-pushed the worktree-release-flow branch from dbf9c73 to 2ef4a0a Compare September 28, 2026 15:01
@oNaiPs
oNaiPs marked this pull request as ready for review September 28, 2026 15:01
Releases were cut by hand: the version was hardcoded in Info.plist, the
only automation was a hub call in main.yml that no longer runs, and builds
were ad-hoc signed, which is why the Homebrew cask got disabled for failing
Gatekeeper (#50).

- Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have
  Info.plist read them.
- Enable the hardened runtime and add the Apple Events entitlement that
  TerminalLauncher needs under it.
- Add scripts/release.sh to bump, commit, tag and push a release.
- Add a Release workflow that runs on version tags: tests, archives,
  exports with Developer ID, notarizes, staples and publishes the zip
  with its sha256 and generated notes. Falls back to an ad-hoc signed
  pre-release when the signing secrets are missing. workflow_dispatch and
  pull requests that touch the release files run it as a dry run that
  uploads the zip as an artifact instead.
- Drop the dead hub step from main.yml.
- Document the process and the required secrets in RELEASING.md.
- Keep the signing secrets in a "release" environment that only version
  tags and main can use, so a pull request run never sees the certificate
  or the notarization key and takes the ad-hoc path.
- Drop the CI token to read-only and pin the SwiftLint action to a commit.
- Move to actions/checkout@v7 and actions/upload-artifact@v7; v4 still
  targets Node.js 20, which the runners warn about.
@oNaiPs
oNaiPs force-pushed the worktree-release-flow branch from 2ef4a0a to 8a5a865 Compare September 28, 2026 15:02
@oNaiPs
oNaiPs merged commit bbb840f into main Sep 28, 2026
4 checks passed
oNaiPs added a commit that referenced this pull request Sep 28, 2026
Releases were cut by hand: the version was hardcoded in Info.plist, the
only automation was a hub call in main.yml that no longer runs, and builds
were ad-hoc signed, which is why the Homebrew cask got disabled for failing
Gatekeeper (#50).

- Move the version to MARKETING_VERSION/CURRENT_PROJECT_VERSION and have
  Info.plist read them.
- Enable the hardened runtime and add the Apple Events entitlement that
  TerminalLauncher needs under it.
- Add scripts/release.sh to bump, commit, tag and push a release.
- Add a Release workflow that runs on version tags: tests, archives,
  exports with Developer ID, notarizes, staples and publishes the zip
  with its sha256 and generated notes. Falls back to an ad-hoc signed
  pre-release when the signing secrets are missing. workflow_dispatch and
  pull requests that touch the release files run it as a dry run that
  uploads the zip as an artifact instead.
- Drop the dead hub step from main.yml.
- Document the process and the required secrets in RELEASING.md.
oNaiPs added a commit that referenced this pull request Sep 28, 2026
@oNaiPs
oNaiPs deleted the worktree-release-flow branch September 28, 2026 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant