Merge pull request #11 from YellowFoxH4XOR/grain-controls #10
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| tags: ["v*"] | |
| permissions: | |
| contents: write | |
| jobs: | |
| release: | |
| runs-on: macos-14 | |
| env: | |
| # Signing + notarization activate only when the repo has these secrets; | |
| # otherwise the build falls back to an ad-hoc signature (still installs, | |
| # but shows Gatekeeper's "unverified developer" prompt). | |
| HAS_SIGNING: ${{ secrets.MACOS_CERT_P12 != '' }} | |
| steps: | |
| - uses: actions/checkout@v5 | |
| - name: Import Developer ID certificate | |
| if: env.HAS_SIGNING == 'true' | |
| env: | |
| CERT_P12: ${{ secrets.MACOS_CERT_P12 }} | |
| CERT_PASSWORD: ${{ secrets.MACOS_CERT_PASSWORD }} | |
| run: | | |
| KEYCHAIN_PWD=$(uuidgen) | |
| echo "$CERT_P12" | base64 --decode > cert.p12 | |
| security create-keychain -p "$KEYCHAIN_PWD" build.keychain | |
| security default-keychain -s build.keychain | |
| security unlock-keychain -p "$KEYCHAIN_PWD" build.keychain | |
| security import cert.p12 -k build.keychain -P "$CERT_PASSWORD" -T /usr/bin/codesign | |
| security set-key-partition-list -S apple-tool:,apple: -s -k "$KEYCHAIN_PWD" build.keychain | |
| rm cert.p12 | |
| IDENTITY=$(security find-identity -v -p codesigning build.keychain | grep "Developer ID Application" | head -1 | sed -E 's/.*"(.*)"/\1/') | |
| echo "SIGN_IDENTITY=$IDENTITY" >> "$GITHUB_ENV" | |
| - name: Build universal DMG | |
| run: make dmg UNIVERSAL=1 SIGN_IDENTITY="${SIGN_IDENTITY:--}" | |
| - name: Notarize and staple | |
| if: env.HAS_SIGNING == 'true' | |
| env: | |
| APPLE_ID: ${{ secrets.APPLE_ID }} | |
| APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }} | |
| APPLE_APP_PASSWORD: ${{ secrets.APPLE_APP_PASSWORD }} | |
| run: | | |
| xcrun notarytool submit dist/Deckle-*.dmg \ | |
| --apple-id "$APPLE_ID" \ | |
| --team-id "$APPLE_TEAM_ID" \ | |
| --password "$APPLE_APP_PASSWORD" \ | |
| --wait | |
| xcrun stapler staple dist/Deckle-*.dmg | |
| - name: Checksum | |
| run: | | |
| cd dist | |
| shasum -a 256 Deckle-*.dmg | tee Deckle.dmg.sha256 | |
| - name: Create GitHub release | |
| uses: softprops/action-gh-release@v3 | |
| with: | |
| files: | | |
| dist/Deckle-*.dmg | |
| dist/Deckle.dmg.sha256 | |
| generate_release_notes: true |