From 0e3232b194e409b2936b618bd71cc2e759fc7b83 Mon Sep 17 00:00:00 2001 From: Luiz Sardinha Date: Sun, 16 Aug 2026 10:45:19 +0200 Subject: [PATCH] ci: producing signed and notarized mac artifacts --- .github/actions/codesign-keychain/action.yml | 47 ++++++++++++++++++++ .github/workflows/continuous-integration.yml | 36 +++++++++++++-- 2 files changed, 80 insertions(+), 3 deletions(-) create mode 100644 .github/actions/codesign-keychain/action.yml diff --git a/.github/actions/codesign-keychain/action.yml b/.github/actions/codesign-keychain/action.yml new file mode 100644 index 000000000..e605860ad --- /dev/null +++ b/.github/actions/codesign-keychain/action.yml @@ -0,0 +1,47 @@ +name: "Apple code-signing keychain" +description: "Imports or cleans up the temporary keychain used to hold the Apple Developer ID certificate" + +inputs: + action: + description: "Which lifecycle step to run: 'import' or 'cleanup'" + required: true + + apple-codesign-p12: + description: "Base64-encoded Apple codesign certificate (.p12), required for 'import'" + required: false + + apple-codesign-p12-pwd: + description: "Password for the Apple codesign certificate (.p12), required for 'import'" + required: false + +runs: + using: "composite" + + steps: + - name: Import certificate + if: inputs.action == 'import' + shell: bash + env: + APPLE_CODESIGN_P12: ${{ inputs.apple-codesign-p12 }} + APPLE_CODESIGN_P12_PWD: ${{ inputs.apple-codesign-p12-pwd }} + run: | + CERTIFICATE_PATH=$RUNNER_TEMP/build_certificate.p12 + KEYCHAIN_PATH=$RUNNER_TEMP/build.keychain + APPLE_CODESIGN_BUILD_PWD=$(openssl rand -hex 32) + echo "::add-mask::$APPLE_CODESIGN_BUILD_PWD" + echo -n "$APPLE_CODESIGN_P12" | base64 --decode > $CERTIFICATE_PATH + security create-keychain -p "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH + security set-keychain-settings -lut 21600 $KEYCHAIN_PATH + security unlock-keychain -p "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH + security import $CERTIFICATE_PATH -k $KEYCHAIN_PATH -P "$APPLE_CODESIGN_P12_PWD" -T /usr/bin/codesign + security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH + security list-keychains -d user -s $KEYCHAIN_PATH + + - name: Clean up keychain + if: inputs.action == 'cleanup' + shell: bash + run: | + if [ -f $RUNNER_TEMP/build.keychain ]; then + security delete-keychain $RUNNER_TEMP/build.keychain + fi + rm -f $RUNNER_TEMP/build_certificate.p12 diff --git a/.github/workflows/continuous-integration.yml b/.github/workflows/continuous-integration.yml index 5ad4a0733..04a9dd6d8 100644 --- a/.github/workflows/continuous-integration.yml +++ b/.github/workflows/continuous-integration.yml @@ -113,15 +113,15 @@ jobs: - name: "macos-arm64" runs-on: macos-15 - timeout: 10 + timeout: 20 qt-version: 6.11.2 config-args: '-DCMAKE_OSX_ARCHITECTURES="arm64" -DCMAKE_OSX_DEPLOYMENT_TARGET=14' - name: "macos-x64" runs-on: macos-15-intel - timeout: 20 + timeout: 30 qt-version: 6.9.3 - config-args: '-DCMAKE_OSX_ARCHITECTURES="x86_64" -DCMAKE_OSX_DEPLOYMENT_TARGET=12 -DCMAKE_OSX_SYSROOT=/Applications/Xcode_16.4.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk' + config-args: '-DCMAKE_OSX_ARCHITECTURES="x86_64" -DCMAKE_OSX_DEPLOYMENT_TARGET=12 -DCMAKE_OSX_SYSROOT=/Applications/Xcode_16.4.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk ${APPLE_CODESIGN_DEV:+-DAPPLE_CODESIGN_DEV="$APPLE_CODESIGN_DEV"}' - name: "debian-x86_64" runs-on: ubuntu-latest @@ -271,8 +271,18 @@ jobs: uses: ./.github/actions/get-version - name: Configure + env: + APPLE_CODESIGN_DEV: ${{ secrets.APPLE_CODESIGN_DEV }} run: ${{env.CMAKE_CONFIGURE}} ${{ matrix.target.config-args }} ${{ steps.get-deps.outputs.vcpkg-cmake-config }} -DPACKAGE_VERSION_LABEL="${{env.DESKFLOW_PACKAGE_VERSION}}" + - name: Import code-signing certificate + if: runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v'))) + uses: ./.github/actions/codesign-keychain + with: + action: import + apple-codesign-p12: ${{ secrets.APPLE_CODESIGN_P12 }} + apple-codesign-p12-pwd: ${{ secrets.APPLE_CODESIGN_P12_PWD }} + - name: Build shell: bash run: | @@ -309,6 +319,26 @@ jobs: cd .. fi + - name: Notarize (macOS) + if: runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v'))) + shell: bash + env: + APPLE_NOTARIZE_ID: ${{ secrets.APPLE_NOTARIZE_ID }} + APPLE_NOTARIZE_PWD: ${{ secrets.APPLE_NOTARIZE_PWD }} + APPLE_CODESIGN_DEV: ${{ secrets.APPLE_CODESIGN_DEV }} + run: | + [[ "$APPLE_CODESIGN_DEV" =~ ^Developer\ ID\ Application:\ .+\ \(([A-Z0-9]+)\)$ ]] + APPLE_NOTARIZE_TEAM="${BASH_REMATCH[1]}" + xcrun codesign -s "${APPLE_CODESIGN_DEV}" build/deskflow[-_]*.dmg + xcrun notarytool submit --apple-id "${APPLE_NOTARIZE_ID}" --password "${APPLE_NOTARIZE_PWD}" --team-id "${APPLE_NOTARIZE_TEAM}" --wait build/deskflow[-_]*.dmg + xcrun stapler staple build/deskflow[-_]*.dmg + + - name: Clean up keychain + if: always() && runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v'))) + uses: ./.github/actions/codesign-keychain + with: + action: cleanup + - name: Check for unexpected repo changes shell: bash run: |