Am 10.09.2026 um 16:32 schrieb Jim Jagielski:
I believe that is just w/ Windows signing, and not Apple.
That was true but even that changed when we switched the service.
I need to experiment a bit around. I would like to keep the signing as
part of the build.
But maybe add it as Flag. Not sure, what is best. cool would be if you
could reference the key to use with -signkey="key name"
If the Flag is not given the package is not signed. Maybe that could be
nice for all build targets. Independant if windows, Linux or Mac.
In case of Linux would be maybe nice for flatpack or snap.
On Sep 10, 2026, at 10:15 AM, Dave Fisher <[email protected]> wrote:
Unless things have changed signing with ASF credentials is not free. If
continuing with Peter’s plan then a distinction needs to be made between
signing a developer’s or ci build, and signing a release build.
On Sep 10, 2026, at 4:24 AM, Jim Jagielski <[email protected]
<mailto:[email protected]>> wrote:
Whatever you want. I'm done.
On Sep 10, 2026, at 6:54 AM, Peter Kovacs <[email protected]
<mailto:[email protected]>> wrote:
Am 10. September 2026 12:24:19 MESZ schrieb Jim Jagielski <[email protected]
<mailto:[email protected]> <mailto:[email protected]>>:
On our builds, yes of course. But we should not force someone who downloads the
source and builds for themselves to also sign that.
Traditionally, we've always signed after we build as a separate process from
building the community build DMGs.
Hopefully that's a bit more clear :)
Ok. And what solution do you propose?
Apple says packaging involves signing. You can not change that.
I am for we release proper signed software or none at all. There is no in
between anymore.
On Sep 10, 2026, at 5:59 AM, Peter Kovacs <[email protected]
<mailto:[email protected]>> wrote:
Am 10. September 2026 11:47:21 MESZ schrieb Jim Jagielski <[email protected]
<mailto:[email protected]>>:
I can't imagine the regular user wanting/needing to sign...
Sorry maybe I was not clear.
I think we should enforce signing on all builds.
The user can always see if that build is from us or someone else. Development
builds will always trigger the gatekeeper.
On Sep 10, 2026, at 5:38 AM, Peter Kovacs <[email protected]
<mailto:[email protected]>> wrote:
Am 10. September 2026 11:30:18 MESZ schrieb Jim Jagielski <[email protected]
<mailto:[email protected]> <mailto:[email protected]>>:
I am also wondering if the actual signing script itself should be in devtools,
somewhere under release-scripts instead.
The process ist to sign the app, then package the image, and then you need to
sign again.
I would rather enforce signing to be mandatory.
What we could put into Devtools maybe is the notarize of the installer. Which
publishes the release at Apple. I guess. And then we could think about a
process to publish in the store.
Cool work.
Yes. I hope this will
On Sep 10, 2026, at 5:14 AM, Jim Jagielski <[email protected]
<mailto:[email protected]>> wrote:
Is there any way you could pull out just the signing bits into a separate
commit?
On Sep 10, 2026, at 12:26 AM, [email protected] <mailto:[email protected]> wrote:
--
Jim
"This is an outrage!"
Tony Harrison
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
<mailto:[email protected]>
<mailto:[email protected]>
For additional commands, e-mail: [email protected]
<mailto:[email protected]> <mailto:[email protected]>
--
Jim
"This is an outrage!"
Tony Harrison
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
--
Jim
"This is an outrage!"
Tony Harrison
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
<mailto:[email protected]>
<mailto:[email protected]>
For additional commands, e-mail: [email protected]
<mailto:[email protected]> <mailto:[email protected]>
--
Jim
"This is an outrage!"
Tony Harrison
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
<mailto:[email protected]>
For additional commands, e-mail: [email protected]
<mailto:[email protected]>
--
Jim
"This is an outrage!"
Tony Harrison
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]