ci: producing signed and notarized mac artifacts

This commit is contained in:
Luiz Sardinha 2026-08-16 10:45:19 +02:00 committed by Chris Rizzitello
parent df4294e949
commit 0e3232b194
2 changed files with 80 additions and 3 deletions

View file

@ -0,0 +1,47 @@
name: "Apple code-signing keychain"
description: "Imports or cleans up the temporary keychain used to hold the Apple Developer ID certificate"
inputs:
action:
description: "Which lifecycle step to run: 'import' or 'cleanup'"
required: true
apple-codesign-p12:
description: "Base64-encoded Apple codesign certificate (.p12), required for 'import'"
required: false
apple-codesign-p12-pwd:
description: "Password for the Apple codesign certificate (.p12), required for 'import'"
required: false
runs:
using: "composite"
steps:
- name: Import certificate
if: inputs.action == 'import'
shell: bash
env:
APPLE_CODESIGN_P12: ${{ inputs.apple-codesign-p12 }}
APPLE_CODESIGN_P12_PWD: ${{ inputs.apple-codesign-p12-pwd }}
run: |
CERTIFICATE_PATH=$RUNNER_TEMP/build_certificate.p12
KEYCHAIN_PATH=$RUNNER_TEMP/build.keychain
APPLE_CODESIGN_BUILD_PWD=$(openssl rand -hex 32)
echo "::add-mask::$APPLE_CODESIGN_BUILD_PWD"
echo -n "$APPLE_CODESIGN_P12" | base64 --decode > $CERTIFICATE_PATH
security create-keychain -p "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH
security set-keychain-settings -lut 21600 $KEYCHAIN_PATH
security unlock-keychain -p "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH
security import $CERTIFICATE_PATH -k $KEYCHAIN_PATH -P "$APPLE_CODESIGN_P12_PWD" -T /usr/bin/codesign
security set-key-partition-list -S apple-tool:,apple:,codesign: -s -k "$APPLE_CODESIGN_BUILD_PWD" $KEYCHAIN_PATH
security list-keychains -d user -s $KEYCHAIN_PATH
- name: Clean up keychain
if: inputs.action == 'cleanup'
shell: bash
run: |
if [ -f $RUNNER_TEMP/build.keychain ]; then
security delete-keychain $RUNNER_TEMP/build.keychain
fi
rm -f $RUNNER_TEMP/build_certificate.p12

View file

@ -113,15 +113,15 @@ jobs:
- name: "macos-arm64" - name: "macos-arm64"
runs-on: macos-15 runs-on: macos-15
timeout: 10 timeout: 20
qt-version: 6.11.2 qt-version: 6.11.2
config-args: '-DCMAKE_OSX_ARCHITECTURES="arm64" -DCMAKE_OSX_DEPLOYMENT_TARGET=14' config-args: '-DCMAKE_OSX_ARCHITECTURES="arm64" -DCMAKE_OSX_DEPLOYMENT_TARGET=14'
- name: "macos-x64" - name: "macos-x64"
runs-on: macos-15-intel runs-on: macos-15-intel
timeout: 20 timeout: 30
qt-version: 6.9.3 qt-version: 6.9.3
config-args: '-DCMAKE_OSX_ARCHITECTURES="x86_64" -DCMAKE_OSX_DEPLOYMENT_TARGET=12 -DCMAKE_OSX_SYSROOT=/Applications/Xcode_16.4.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk' config-args: '-DCMAKE_OSX_ARCHITECTURES="x86_64" -DCMAKE_OSX_DEPLOYMENT_TARGET=12 -DCMAKE_OSX_SYSROOT=/Applications/Xcode_16.4.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk ${APPLE_CODESIGN_DEV:+-DAPPLE_CODESIGN_DEV="$APPLE_CODESIGN_DEV"}'
- name: "debian-x86_64" - name: "debian-x86_64"
runs-on: ubuntu-latest runs-on: ubuntu-latest
@ -271,8 +271,18 @@ jobs:
uses: ./.github/actions/get-version uses: ./.github/actions/get-version
- name: Configure - name: Configure
env:
APPLE_CODESIGN_DEV: ${{ secrets.APPLE_CODESIGN_DEV }}
run: ${{env.CMAKE_CONFIGURE}} ${{ matrix.target.config-args }} ${{ steps.get-deps.outputs.vcpkg-cmake-config }} -DPACKAGE_VERSION_LABEL="${{env.DESKFLOW_PACKAGE_VERSION}}" run: ${{env.CMAKE_CONFIGURE}} ${{ matrix.target.config-args }} ${{ steps.get-deps.outputs.vcpkg-cmake-config }} -DPACKAGE_VERSION_LABEL="${{env.DESKFLOW_PACKAGE_VERSION}}"
- name: Import code-signing certificate
if: runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v')))
uses: ./.github/actions/codesign-keychain
with:
action: import
apple-codesign-p12: ${{ secrets.APPLE_CODESIGN_P12 }}
apple-codesign-p12-pwd: ${{ secrets.APPLE_CODESIGN_P12_PWD }}
- name: Build - name: Build
shell: bash shell: bash
run: | run: |
@ -309,6 +319,26 @@ jobs:
cd .. cd ..
fi fi
- name: Notarize (macOS)
if: runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v')))
shell: bash
env:
APPLE_NOTARIZE_ID: ${{ secrets.APPLE_NOTARIZE_ID }}
APPLE_NOTARIZE_PWD: ${{ secrets.APPLE_NOTARIZE_PWD }}
APPLE_CODESIGN_DEV: ${{ secrets.APPLE_CODESIGN_DEV }}
run: |
[[ "$APPLE_CODESIGN_DEV" =~ ^Developer\ ID\ Application:\ .+\ \(([A-Z0-9]+)\)$ ]]
APPLE_NOTARIZE_TEAM="${BASH_REMATCH[1]}"
xcrun codesign -s "${APPLE_CODESIGN_DEV}" build/deskflow[-_]*.dmg
xcrun notarytool submit --apple-id "${APPLE_NOTARIZE_ID}" --password "${APPLE_NOTARIZE_PWD}" --team-id "${APPLE_NOTARIZE_TEAM}" --wait build/deskflow[-_]*.dmg
xcrun stapler staple build/deskflow[-_]*.dmg
- name: Clean up keychain
if: always() && runner.os == 'macOS' && ((github.ref == 'refs/heads/master') || (contains(github.ref, '/tags/v')))
uses: ./.github/actions/codesign-keychain
with:
action: cleanup
- name: Check for unexpected repo changes - name: Check for unexpected repo changes
shell: bash shell: bash
run: | run: |