fix(release): disable mac notarization so unsigned builds don't fail CI - #40
Merged
Merged
Conversation
notarize:true makes electron-builder attempt Apple notarization on the mac runner; with no APPLE_ID/APPLE_APP_SPECIFIC_PASSWORD/APPLE_TEAM_ID secrets set it errors out and blocks the whole release pipeline rather than falling back to an unsigned artifact. Set false so the first v* tag produces green mac builds (Gatekeeper 'unidentified developer' prompt on open). Flip back to true once the Apple signing secrets are configured in repo settings.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #39 (enabling fork releases).
Problem
package.jsonhasbuild.mac.notarize: true. On av*tag, the mac build job calls electron-builder which attempts Apple notarization. With noAPPLE_ID/APPLE_APP_SPECIFIC_PASSWORD/APPLE_TEAM_IDsecrets configured in repo settings, it errors out — blocking the entire release pipeline (linux + win included), not falling back to an unsigned build.Fix
notarize: falseso the first release produces green mac builds. Users get the usual Gatekeeper 'unidentified developer' prompt on first open; linux AppImage/deb and the auto-update feed are unaffected.Flip back to
trueonce the three Apple signing secrets are set in repo settings, if signed mac builds are wanted later.Surfaced by the review of #39.