| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
This local repository is ready to become the public slopus/.github repository. It centralizes the organization-owned macOS signing and notarization boundary.
Export only Developer ID Application: Bulka, LLC (466DQWDR8C) and its private key from Keychain Access as an encrypted .p12. Do not export the separate Apple Development identity.
In App Store Connect, create a team API key with Developer access and download its one-time AuthKey_KEYID.p8 file. Record the issuer UUID.
Give GitHub CLI organization-secret permission:
gh auth refresh --hostname github.com --scopes admin:orgConfigure the selected-repository organization secrets:
scripts/configure-macos-secrets.sh \
--certificate /secure/path/developer-id.p12 \
--notary-key /secure/path/AuthKey_KEYID.p8 \
--notary-issuer ISSUER_UUID \
--repositories happy2Create and publish this repository:
gh repo create slopus/.github --public --source . --remote origin --pushNever commit either credential file. Keep organization secrets limited to selected trusted repositories: a repository with access can execute code that reads them during a workflow.
After publishing and tagging this repository as v1, a trusted repository can call:
jobs:
mac:
uses: slopus/.github/.github/workflows/macos-release.yml@v1
with:
runner: macos-14
build-command: pnpm desktop:mac:release -- --arch arm64 --flavor all
artifact-name: signed-macos-arm64
artifact-path: |
packages/desktop/release/**/*.dmg
packages/desktop/release/**/*.zip
packages/desktop/release/**/*.blockmap
packages/desktop/release/**/*-mac.yml
secrets: inheritUse a reviewed version tag or immutable commit SHA, never a moving branch, for production callers.
| Back | FazBrowse Home | New Git URL |