feat: build, sign and notarize macOS app bundle in CI - #2614
Merged
Merged
Conversation
- new build-macos-app job: Lazarus 4.8 install, make build-macos, create-macos-app.sh bundle/sign/notarize, artifact upload - with MACOS_CODESIGN_IDENTITY + APPLE_NOTARY secrets: full Developer ID signing and notarization; without: ad-hoc signed fallback bundle - signing cert imported into ephemeral keychain, cleaned up after run - release job attaches the bundle as HeidiSQL-macos-<tag>.zip - create-macos-app.sh: env-overridable identity/team/notary profile, --adhoc flag, executable auto-detection (out/ vs out/macos/), tolerant openssl@1.1 install Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
…t allowed in if:) Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
…-u unbound variable) Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
Co-authored-by: ansgarbecker <ansgarbecker@users.noreply.github.com>
ansgarbecker
marked this pull request as ready for review
September 28, 2026 15:31
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
build-macos-appjob: builds the signed + notarizedheidisql.appbundle in CI, no local Mac mini needed anymorecreate-macos-app.shmade CI-capable: identity/team/notary profile overridable via env vars, new--adhocflag, executable path auto-detection, tolerantopenssl@1.1install (deprecated in Homebrew)How it works
MACOS_CODESIGN_IDENTITY,MACOS_CERTIFICATE_P12_BASE64,MACOS_CERTIFICATE_PASSWORD,APPLE_NOTARY_APPLE_ID/TEAM_ID/PASSWORD): certificate is imported into an ephemeral keychain, bundle is fully Developer ID signed and notarized vianotarytool— identical result to the local buildgithub.ref_type == 'tag'only) now also downloads and attaches the bundle asHeidiSQL-macos-<tag>.zipTesting without triggering a release
lazarusruns the bundle job and uploadsmacos-app-bundleas a workflow artifact — nothing is releasedRequired repository secrets
MACOS_CERTIFICATE_P12_BASE64base64 -i cert.p12)MACOS_CERTIFICATE_PASSWORDMACOS_CODESIGN_IDENTITYDeveloper ID Application: Ansgar Becker (QBD4CC6FH3)MACOS_TEAM_IDQBD4CC6FH3APPLE_NOTARY_APPLE_IDAPPLE_NOTARY_TEAM_IDQBD4CC6FH3APPLE_NOTARY_PASSWORDVerification
bash -n create-macos-app.sh— syntax OKrelease.needschecked programmatically