Skip to content

feat(ci): add notarized release workflow - #16

Open
cchandurkar wants to merge 12 commits into
mainfrom
chore/release-notarization-workflow
Open

cchandurkar wants to merge 12 commits into
mainfrom
chore/release-notarization-workflow

Conversation

@cchandurkar

Copy link
Copy Markdown
Owner

What

  • New .github/workflows/release.yml: on tag push (v*.*.*) or manual dispatch, builds installers on macOS/Windows/Linux via npm run release, uploads them as workflow artifacts, then a publish job creates/updates the GitHub Release for that tag with gh release create/gh release upload.
  • macOS leg signs with a Developer ID Application cert and notarizes via notarytool, gated on 6 repo secrets (MAC_CERTIFICATE_P12_BASE64, MAC_CERTIFICATE_PASSWORD, APPLE_API_KEY_BASE64, APPLE_API_KEY_ID, APPLE_API_ISSUER, APPLE_TEAM_ID), scoped so they cannot leak into the Windows/Linux legs.
  • README: new "Releasing (macOS notarization)" section documenting the tag flow and secrets table; cross-linked from the two existing "before distributing" notes, the Available Scripts table, and the CI blurb.

Why

Follow-up to the PR review discussion on adding notarized release artifacts.

Notes

  • No electron-builder.json changes needed — package:release already passes -c.mac.notarize=true as a CLI override, so local npm run package stays fast/unsigned.
  • This only triggers on tag push/workflow_dispatch, so merging has no effect on ci.yml's existing push/PR triggers.
  • macOS leg will fail until the secrets above are added (repo owner is setting those up separately); Windows/Linux legs work regardless.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant