Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 34 additions & 1 deletion .github/workflows/build-mac.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,12 +55,44 @@ jobs:
run: npm run build:mac
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# If signing secrets are missing, force unsigned build instead of producing a partially-signed broken app.
CSC_IDENTITY_AUTO_DISCOVERY: ${{ secrets.CSC_LINK != '' && 'true' || 'false' }}
# macOS codesign (Developer ID Application certificate in .p12)
CSC_LINK: ${{ secrets.CSC_LINK }}
CSC_KEY_PASSWORD: ${{ secrets.CSC_KEY_PASSWORD }}
# macOS notarization (Apple account API)
APPLE_ID: ${{ secrets.APPLE_ID }}
APPLE_APP_SPECIFIC_PASSWORD: ${{ secrets.APPLE_APP_SPECIFIC_PASSWORD }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}

- name: Verify generated macOS installers are valid
run: |
set -euo pipefail
ls -lah dist

dmg_file=$(find dist -maxdepth 1 -name '*.dmg' | head -n1)
if [ -z "$dmg_file" ]; then
echo "No DMG generated"
exit 1
fi

echo "Checking DMG: $dmg_file"
hdiutil verify "$dmg_file"

# Keep ZIP artifact as a fallback channel for users who still encounter DMG issues.
zip_file=$(find dist -maxdepth 1 -name '*.zip' | head -n1 || true)
if [ -n "${zip_file:-}" ]; then
echo "Checking ZIP: $zip_file"
unzip -t "$zip_file"
fi

- name: Upload Mac Artifacts
uses: actions/upload-artifact@v4
with:
name: mac-build
path: dist/*.dmg
path: |
dist/*.dmg
dist/*.zip
retention-days: 5

build-windows:
Expand Down Expand Up @@ -118,4 +150,5 @@ jobs:
generate_release_notes: true
files: |
release-assets/*.dmg
release-assets/*.zip
release-assets/*.exe
12 changes: 12 additions & 0 deletions assets/macos/entitlements.mac.inherit.plist
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
<key>com.apple.security.cs.disable-library-validation</key>
<true/>
</dict>
</plist>
12 changes: 12 additions & 0 deletions assets/macos/entitlements.mac.plist
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
<key>com.apple.security.cs.disable-library-validation</key>
<true/>
</dict>
</plist>
11 changes: 9 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,15 @@
"backgroundColor": "#FFFFFF"
},
"mac": {
"target": "dmg",
"icon": "assets/icon.icns"
"target": [
"dmg",
"zip"
],
"icon": "assets/icon.icns",
"hardenedRuntime": true,
"gatekeeperAssess": false,
"entitlements": "assets/macos/entitlements.mac.plist",
"entitlementsInherit": "assets/macos/entitlements.mac.inherit.plist"
},
"files": [
"main.js",
Expand Down
Loading