ci(release): sign and notarize the macOS bundle, and bump the Homebrew cask

An unsigned bundle on a current macOS opens to a malware warning with no obvious way past it, and
the way past it that does exist teaches people to click through exactly the warning worth reading.
The build now signs with a Developer ID certificate and notarizes with an App Store Connect API
key, which is also what does the App Store upload, so there is one credential to rotate.

The verification step is the point. codesign only says a signature is internally consistent;
spctl is what a person double-clicking the file actually meets, and it does not pass until the
notarization ticket is stapled.

A final job rewrites the version and sha256 in the tap's cask, using an SSH deploy key rather than
a token so a leak from a release job cannot reach the app repositories.

Also fixes Cargo.lock drifting a version behind on every release: the bump wrote Cargo.toml but
never staged the lock, so any fresh build dirtied the tree.

Claude-Session: https://claude.ai/code/session_018HwEWvoE1NkkUjJCMLSnup
This commit is contained in:
pj committed 2026-08-31 17:25:51 +05:30
1 parent d8c47bb6f0
commit 39d4097773
4 files changed
+101 -5

No files matched your search

+1 -1
View File
@@ -4713,7 +4713,7 @@ checksum = "3e2e65a1a2e43cfcb47a895c4c8b10d1f4a61097f9f254f183aee60cad9c651d"
[[package]]
name = "margin-app"
version = "0.1.16"
version = "0.1.17"
dependencies = [
"base64 0.22.1",
"fontdb",
+11
View File
@@ -0,0 +1,11 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<!-- Margin's only cryptography is TLS for the Google Drive API and the SHA-256 that PKCE
needs, both of which are exempt. Declaring it here rather than in App Store Connect means
the question is not asked again on every submission. -->
<key>ITSAppUsesNonExemptEncryption</key>
<false/>
</dict>
</plist>
+9 -1
View File
@@ -36,6 +36,14 @@
"icons/[email protected]",
"icons/icon.icns",
"icons/icon.ico"
]
],
"category": "Productivity",
"shortDescription": "A calm, offline writing studio for authors",
"longDescription": "Write your book, set it in real book typography, and export print-ready PDF and ebook files for every store. Everything happens on your machine.",
"copyright": "Copyright © 2026 Priyanshu Jain",
"macOS": {
"minimumSystemVersion": "10.15",
"hardenedRuntime": true
}
}
}