Skip to content

Merge pull request #11 from YellowFoxH4XOR/grain-controls #10

Merge pull request #11 from YellowFoxH4XOR/grain-controls

Merge pull request #11 from YellowFoxH4XOR/grain-controls #10

Workflow file for this run

name: Release
on:
push:
tags: ["v*"]
permissions:
contents: write
jobs:
release:
runs-on: macos-14
env:
# Signing + notarization activate only when the repo has these secrets;
# otherwise the build falls back to an ad-hoc signature (still installs,
# but shows Gatekeeper's "unverified developer" prompt).
HAS_SIGNING: ${{ secrets.MACOS_CERT_P12 != '' }}
steps:
- uses: actions/checkout@v5
- name: Import Developer ID certificate
if: env.HAS_SIGNING == 'true'
env:
CERT_P12: ${{ secrets.MACOS_CERT_P12 }}
CERT_PASSWORD: ${{ secrets.MACOS_CERT_PASSWORD }}
run: |
KEYCHAIN_PWD=$(uuidgen)
echo "$CERT_P12" | base64 --decode > cert.p12
security create-keychain -p "$KEYCHAIN_PWD" build.keychain
security default-keychain -s build.keychain
security unlock-keychain -p "$KEYCHAIN_PWD" build.keychain
security import cert.p12 -k build.keychain -P "$CERT_PASSWORD" -T /usr/bin/codesign
security set-key-partition-list -S apple-tool:,apple: -s -k "$KEYCHAIN_PWD" build.keychain
rm cert.p12
IDENTITY=$(security find-identity -v -p codesigning build.keychain | grep "Developer ID Application" | head -1 | sed -E 's/.*"(.*)"/\1/')
echo "SIGN_IDENTITY=$IDENTITY" >> "$GITHUB_ENV"
- name: Build universal DMG
run: make dmg UNIVERSAL=1 SIGN_IDENTITY="${SIGN_IDENTITY:--}"
- name: Notarize and staple
if: env.HAS_SIGNING == 'true'
env:
APPLE_ID: ${{ secrets.APPLE_ID }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_APP_PASSWORD: ${{ secrets.APPLE_APP_PASSWORD }}
run: |
xcrun notarytool submit dist/Deckle-*.dmg \
--apple-id "$APPLE_ID" \
--team-id "$APPLE_TEAM_ID" \
--password "$APPLE_APP_PASSWORD" \
--wait
xcrun stapler staple dist/Deckle-*.dmg
- name: Checksum
run: |
cd dist
shasum -a 256 Deckle-*.dmg | tee Deckle.dmg.sha256
- name: Create GitHub release
uses: softprops/action-gh-release@v3
with:
files: |
dist/Deckle-*.dmg
dist/Deckle.dmg.sha256
generate_release_notes: true