Sign final Darwin universal release binary (#61)

* Sign final Darwin universal release binary

* Use GoReleaser's built-in macOS signer

* Inline Darwin signature verification
This commit is contained in:
Fedor Kororkov
2026-08-18 17:39:21 -07:00
committed by GitHub
parent 1375c77582
commit 94a27a6724
2 changed files with 23 additions and 0 deletions
+2
View File
@@ -52,6 +52,8 @@ jobs:
GITHUB_TOKEN: ${{ steps.release-token.outputs.token }}
GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }}
HOMEBREW_TAP_GITHUB_TOKEN: ${{ steps.tap-token.outputs.token }}
MACOS_SIGN_P12: ${{ secrets.MACOS_SIGN_P12 }}
MACOS_SIGN_PASSWORD: ${{ secrets.MACOS_SIGN_PASSWORD }}
dry-run:
name: Release (Dry Run)
+21
View File
@@ -39,11 +39,32 @@ universal_binaries:
- replace: true
ids:
- darwin
# GoReleaser's macOS signer uses the executable name as its identifier.
name_template: tart-guest-agent
hooks:
post: '{{ if .IsSnapshot }}codesign --force --sign - --identifier tart-guest-agent --timestamp=none "{{ .Path }}"{{ else }}true{{ end }}'
notarize:
macos:
- enabled: '{{ not .IsSnapshot }}'
sign:
certificate: "{{ .Env.MACOS_SIGN_P12 }}"
password: "{{ .Env.MACOS_SIGN_PASSWORD }}"
archives:
- name_template: "{{ .ProjectName }}-{{ .Os }}-{{ .Arch }}"
formats:
- tar.gz
hooks:
# The built-in macOS signer runs before archiving.
before:
- cmd: >-
{{ if eq .Os "darwin" }}
sh -ec 'lipo "$1" -verify_arch arm64 x86_64;
codesign --verify --all-architectures --strict "$1";
for arch in arm64 x86_64; do codesign --verify --strict --arch "$arch" "$1"; done'
_ "{{ .Dist }}/tart-guest-agent_darwin_all/tart-guest-agent"
{{ else }}true{{ end }}
release:
prerelease: auto