mirror of
https://github.com/priyanshujain/margin.git
synced 2026-10-02 11:07:04 +00:00
39d40977736b6b3a2d0c60c7e22b5b6f6eb8fff4
An unsigned bundle on a current macOS opens to a malware warning with no obvious way past it, and the way past it that does exist teaches people to click through exactly the warning worth reading. The build now signs with a Developer ID certificate and notarizes with an App Store Connect API key, which is also what does the App Store upload, so there is one credential to rotate. The verification step is the point. codesign only says a signature is internally consistent; spctl is what a person double-clicking the file actually meets, and it does not pass until the notarization ticket is stapled. A final job rewrites the version and sha256 in the tap's cask, using an SSH deploy key rather than a token so a leak from a release job cannot reach the app repositories. Also fixes Cargo.lock drifting a version behind on every release: the bump wrote Cargo.toml but never staged the lock, so any fresh build dirtied the tree. Claude-Session: https://claude.ai/code/session_018HwEWvoE1NkkUjJCMLSnup
margin
Write your book. Own every word. A calm, offline studio to write, format, and publish your book to every store and to print.
Languages
TypeScript
46.6%
CSS
13.7%
Rust
12%
Astro
11.2%
HTML
8.4%
Other
8.1%