Fix release signing pipeline and stop advertising the app as unsigned - #28
Open
royalbhati wants to merge 2 commits into
Open
royalbhati wants to merge 2 commits into
royalbhati wants to merge 2 commits into
Conversation
The release workflow built with CODE_SIGN_IDENTITY="-" (ad-hoc) and published the result, so any tag push could ship an unsigned build that trips Gatekeeper. Releases now: - fail fast if signing secrets are absent, rather than silently going ad-hoc - import the Developer ID cert into a throwaway keychain - build with hardened runtime and a secure timestamp - notarize via notarytool and staple the ticket - gate publishing on spctl reporting "Notarized Developer ID" Requires secrets: MACOS_CERT_P12_BASE64, MACOS_CERT_PASSWORD, APPLE_ID, APPLE_APP_SPECIFIC_PASSWORD. build.yml also runs the 100 HopTabPro tests, which CI never executed, and now runs on pushes to main rather than pull requests only.
HopTab has been Developer ID signed and notarized since 1.4.0, but the README still said "ad-hoc signed (not notarized)" and instructed people to run xattr to bypass Gatekeeper — the scariest possible framing right before asking for Accessibility permission. - README: drop both xattr commands and the not-notarized note - release.yml: same fix in the release-notes template - hoptab.rb: sync the stale root copy (1.2.0) to match the real tap (1.4.0) - gitignore internal strategy docs and local demo recordings (scripts/release.sh carries the same stale text and has been fixed locally, but scripts/ is gitignored so it is not part of this commit.)
royalbhati
force-pushed
the
fix/release-signing-and-install-docs
branch
from
August 30, 2026 03:46
c1e312c to
448b93c
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Two problems found while auditing why installs are low.
1. The release workflow could ship an unsigned build.
release.ymlbuilt withCODE_SIGN_IDENTITY="-"(ad-hoc) and published the result on anyv*tag push. Shipped 1.4.0 is properly notarized, so something outside CI produced it — but the workflow remains a live trap: the nextscripts/release.shrun pushes a tag, CI builds ad-hoc, andrelease.shthen points the Homebrew cask at whatever CI produced.2. The README told every visitor the app was unsigned.
Verified against the shipped 1.4.0 binary:
The README still said "HopTab is ad-hoc signed (not notarized)" and gave two
xattrcommands to bypass Gatekeeper — the scariest possible framing immediately before asking for Accessibility permission. The notarization work was done and the trust penalty was still being paid.What changed
Release pipeline
notarytooland staples the ticketspctlreportingsource=Notarized Developer IDCI
build.ymlnow runs the 100 HopTabPro tests, which CI never executedmain, not just PRsDocs
xattrcommands and the not-notarized note removedrelease.ymlrelease-notes template: same fix, plus the Homebrew one-linerhoptab.rb: stale root copy synced 1.2.0 → 1.4.0 to match the real tap.gitignore: internal strategy docs and local demo recordingsBefore merging
The release job needs these secrets, or every release will now fail (deliberately — that's the point):
MACOS_CERT_P12_BASE64.p12, base64MACOS_CERT_PASSWORD.p12APPLE_IDAPPLE_APP_SPECIFIC_PASSWORDTeam ID
GP4Y23ZTR6is set inline in the workflow.Worth reconciling how 1.4.0 actually got signed before cutting 1.5 — if it was a manual Xcode archive, this workflow replaces that step.