Skip to content

feat: build, sign and notarize macOS app bundle in CI - #2614

Merged
ansgarbecker merged 6 commits into
lazarusfrom
vibe/macos-app-bundle-ci
Sep 28, 2026
Merged

ansgarbecker merged 6 commits into
lazarusfrom
vibe/macos-app-bundle-ci

Conversation

@ansgarbecker

Copy link
Copy Markdown
Collaborator

Summary

  • New build-macos-app job: builds the signed + notarized heidisql.app bundle in CI, no local Mac mini needed anymore
  • create-macos-app.sh made CI-capable: identity/team/notary profile overridable via env vars, new --adhoc flag, executable path auto-detection, tolerant openssl@1.1 install (deprecated in Homebrew)

How it works

  • With signing secrets (MACOS_CODESIGN_IDENTITY, MACOS_CERTIFICATE_P12_BASE64, MACOS_CERTIFICATE_PASSWORD, APPLE_NOTARY_APPLE_ID/TEAM_ID/PASSWORD): certificate is imported into an ephemeral keychain, bundle is fully Developer ID signed and notarized via notarytool — identical result to the local build
  • Without secrets (e.g. forks, or before you set the secrets): the job falls back to an ad-hoc signed bundle, so the pipeline is testable immediately — no tag and no release needed, the artifact is downloadable from the workflow run
  • Release job (github.ref_type == 'tag' only) now also downloads and attaches the bundle as HeidiSQL-macos-<tag>.zip

Testing without triggering a release

  • Every push/PR to lazarus runs the bundle job and uploads macos-app-bundle as a workflow artifact — nothing is released
  • Once the six secrets are configured, the same run automatically switches to full signing + notarization

Required repository secrets

Secret Content
MACOS_CERTIFICATE_P12_BASE64 Developer ID Application cert as .p12, base64-encoded (base64 -i cert.p12)
MACOS_CERTIFICATE_PASSWORD Password of the .p12 export
MACOS_CODESIGN_IDENTITY Developer ID Application: Ansgar Becker (QBD4CC6FH3)
MACOS_TEAM_ID QBD4CC6FH3
APPLE_NOTARY_APPLE_ID Apple ID used for notarization
APPLE_NOTARY_TEAM_ID QBD4CC6FH3
APPLE_NOTARY_PASSWORD App-specific Apple ID password (appleid.apple.com)

Verification

  • bash -n create-macos-app.sh — syntax OK
  • YAML validated; job graph and release.needs checked programmatically

mistral-vibe and others added 6 commits September 27, 2026 17:26
- new build-macos-app job: Lazarus 4.8 install, make build-macos,
  create-macos-app.sh bundle/sign/notarize, artifact upload
- with MACOS_CODESIGN_IDENTITY + APPLE_NOTARY secrets: full Developer ID
  signing and notarization; without: ad-hoc signed fallback bundle
- signing cert imported into ephemeral keychain, cleaned up after run
- release job attaches the bundle as HeidiSQL-macos-<tag>.zip
- create-macos-app.sh: env-overridable identity/team/notary profile,
  --adhoc flag, executable auto-detection (out/ vs out/macos/),
  tolerant openssl@1.1 install

Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
…t allowed in if:)

Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
…-u unbound variable)

Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
@ansgarbecker
ansgarbecker marked this pull request as ready for review September 28, 2026 15:31
@ansgarbecker
ansgarbecker merged commit 1910c5c into lazarus Sep 28, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants