| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
release: ship a notarized DMG instead of a bare zip
Distributing the app as a zip meant users ran it straight from ~/Downloads,
where macOS App Translocation executes a quarantined app from a random
read-only path and it fails to open ("can't be opened") unless they
manually strip the quarantine xattr. A DMG with an /Applications shortcut
guides users to drag the app into /Applications, avoiding translocation, so
it launches cleanly on first double-click with no terminal commands. Sign,
notarize, and staple the DMG itself as well.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
release: ship a notarized DMG instead of a bare zip
Distributing the app as a zip meant users ran it straight from ~/Downloads,
where macOS App Translocation executes a quarantined app from a random
read-only path and it fails to open ("can't be opened") unless they
manually strip the quarantine xattr. A DMG with an /Applications shortcut
guides users to drag the app into /Applications, avoiding translocation, so
it launches cleanly on first double-click with no terminal commands. Sign,
notarize, and staple the DMG itself as well.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
release: strip device-locked provisioning profile before re-signing
Xcode embeds a Development provisioning profile (Mac Team Provisioning
Profile) that hard-locks the app to registered Macs. Notarization and
Gatekeeper still pass, but the app refuses to launch ("can't be opened")
on any other machine. Remove Contents/embedded.provisionprofile before
the Developer ID re-sign so distributed builds run everywhere.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
release: strip device-locked provisioning profile before re-signing
Xcode embeds a Development provisioning profile (Mac Team Provisioning
Profile) that hard-locks the app to registered Macs. Notarization and
Gatekeeper still pass, but the app refuses to launch ("can't be opened")
on any other machine. Remove Contents/embedded.provisionprofile before
the Developer ID re-sign so distributed builds run everywhere.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
release: sign with Developer ID + notarize for public distribution
The prior release script shipped an Apple Development-signed app, which
Gatekeeper rejects on any Mac not registered to the dev account ("cannot
open app"). Re-sign the built app with the Developer ID Application cert
and a hardened runtime, submit to Apple's notary service, staple the
ticket, and verify with spctl before publishing.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
| Back | FazBrowse Home | New Git URL |