Sign and verify macOS release binaries before upload - #11
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #9.
The v0.25.0 Apple Silicon executable was reported to have an invalid embedded signature, causing macOS to kill it before startup. Ad-hoc sign macOS binaries after compilation with Bun's documented JavaScriptCore entitlements, then require strict signature verification before artifact upload. Release checksums cover the final signed bytes.
Build and smoke-test Intel and ARM macOS binaries natively in CI and releases, including help/version, document reading, and schema validation. Update signing and recovery documentation, including resolving mise shims and using the Bun package fallback without PATH shadowing. Existing published assets are unchanged; this fixes future builds. Ad-hoc signing does not provide Developer ID identity or notarization.
Test plan
bun run check(lint, types, dead code); shell syntax, entitlement plist, workflow YAML, and diff checks.macOS 27, native Intel execution, and remote GitHub workflows remain unverified locally. No LibreOffice checks were run during final review. The pre-commit full-suite hook was skipped to avoid launching LibreOffice; the checks above were run separately.