How can that be? Apple signing doesn't use a service afaik.
> On Sep 10, 2026, at 1:33 PM, [email protected] wrote:
>
>
> Am 10.09.2026 um 16:32 schrieb Jim Jagielski:
>> I believe that is just w/ Windows signing, and not Apple.
>
> That was true but even that changed when we switched the service.
>
> I need to experiment a bit around. I would like to keep the signing as part
> of the build.
>
> But maybe add it as Flag. Not sure, what is best. cool would be if you could
> reference the key to use with -signkey="key name"
> If the Flag is not given the package is not signed. Maybe that could be nice
> for all build targets. Independant if windows, Linux or Mac.
> In case of Linux would be maybe nice for flatpack or snap.
>
>>
>>> On Sep 10, 2026, at 10:15 AM, Dave Fisher <[email protected]
>>> <mailto:[email protected]>> wrote:
>>>
>>> Unless things have changed signing with ASF credentials is not free. If
>>> continuing with Peter’s plan then a distinction needs to be made between
>>> signing a developer’s or ci build, and signing a release build.
>>>
>>>> On Sep 10, 2026, at 4:24 AM, Jim Jagielski <[email protected]
>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote:
>>>>
>>>> Whatever you want. I'm done.
>>>>
>>>>> On Sep 10, 2026, at 6:54 AM, Peter Kovacs <[email protected]
>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote:
>>>>>
>>>>>
>>>>>
>>>>> Am 10. September 2026 12:24:19 MESZ schrieb Jim Jagielski
>>>>> <[email protected] <mailto:[email protected]> <mailto:[email protected]>
>>>>> <mailto:[email protected]>>:
>>>>>> On our builds, yes of course. But we should not force someone who
>>>>>> downloads the source and builds for themselves to also sign that.
>>>>>>
>>>>>> Traditionally, we've always signed after we build as a separate process
>>>>>> from building the community build DMGs.
>>>>>>
>>>>>> Hopefully that's a bit more clear :)
>>>>> Ok. And what solution do you propose?
>>>>> Apple says packaging involves signing. You can not change that.
>>>>> I am for we release proper signed software or none at all. There is no in
>>>>> between anymore.
>>>>>>> On Sep 10, 2026, at 5:59 AM, Peter Kovacs <[email protected]
>>>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote:
>>>>>>>
>>>>>>>
>>>>>>>
>>>>>>> Am 10. September 2026 11:47:21 MESZ schrieb Jim Jagielski
>>>>>>> <[email protected] <mailto:[email protected]> <mailto:[email protected]>>:
>>>>>>>> I can't imagine the regular user wanting/needing to sign...
>>>>>>> Sorry maybe I was not clear.
>>>>>>> I think we should enforce signing on all builds.
>>>>>>> The user can always see if that build is from us or someone else.
>>>>>>> Development builds will always trigger the gatekeeper.
>>>>>>>>> On Sep 10, 2026, at 5:38 AM, Peter Kovacs <[email protected]
>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>>
>>>>>>>>> wrote:
>>>>>>>>>
>>>>>>>>>
>>>>>>>>>
>>>>>>>>> Am 10. September 2026 11:30:18 MESZ schrieb Jim Jagielski
>>>>>>>>> <[email protected] <mailto:[email protected]> <mailto:[email protected]>
>>>>>>>>> <mailto:[email protected]>>:
>>>>>>>>>> I am also wondering if the actual signing script itself should be in
>>>>>>>>>> devtools, somewhere under release-scripts instead.
>>>>>>>>> The process ist to sign the app, then package the image, and then you
>>>>>>>>> need to sign again.
>>>>>>>>>
>>>>>>>>> I would rather enforce signing to be mandatory.
>>>>>>>>> What we could put into Devtools maybe is the notarize of the
>>>>>>>>> installer. Which publishes the release at Apple. I guess. And then we
>>>>>>>>> could think about a process to publish in the store.
>>>>>>>>>> Cool work.
>>>>>>>>> Yes. I hope this will
>>>>>>>>>>> On Sep 10, 2026, at 5:14 AM, Jim Jagielski <[email protected]
>>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]>> wrote:
>>>>>>>>>>>
>>>>>>>>>>> Is there any way you could pull out just the signing bits into a
>>>>>>>>>>> separate commit?
>>>>>>>>>>>
>>>>>>>>>>>> On Sep 10, 2026, at 12:26 AM, [email protected]
>>>>>>>>>>>> <mailto:[email protected]> <mailto:[email protected]> wrote:
>>>>>>>>>>>>
>>>>>>>>>>>>
>>>>>>>>>> --
>>>>>>>>>> Jim
>>>>>>>>>> "This is an outrage!"
>>>>>>>>>> Tony Harrison
>>>>>>>>>>
>>>>>>>>> ---------------------------------------------------------------------
>>>>>>>>> To unsubscribe, e-mail: [email protected]
>>>>>>>>> <mailto:[email protected]>
>>>>>>>>> <mailto:[email protected]>
>>>>>>>>> <mailto:[email protected]>
>>>>>>>>> For additional commands, e-mail: [email protected]
>>>>>>>>> <mailto:[email protected]>
>>>>>>>>> <mailto:[email protected]>
>>>>>>>>> <mailto:[email protected]>
>>>>>>>> --
>>>>>>>> Jim
>>>>>>>> "This is an outrage!"
>>>>>>>> Tony Harrison
>>>>>>>>
>>>>>>> ---------------------------------------------------------------------
>>>>>>> To unsubscribe, e-mail: [email protected]
>>>>>>> For additional commands, e-mail: [email protected]
>>>>>>>
>>>>>> --
>>>>>> Jim
>>>>>> "This is an outrage!"
>>>>>> Tony Harrison
>>>>>>
>>>>> ---------------------------------------------------------------------
>>>>> To unsubscribe, e-mail: [email protected]
>>>>> <mailto:[email protected]>
>>>>> <mailto:[email protected]>
>>>>> <mailto:[email protected]>
>>>>> For additional commands, e-mail: [email protected]
>>>>> <mailto:[email protected]>
>>>>> <mailto:[email protected]>
>>>>> <mailto:[email protected]>
>>>> --
>>>> Jim
>>>> "This is an outrage!"
>>>> Tony Harrison
>>>>
>>>
>>> ---------------------------------------------------------------------
>>> To unsubscribe, e-mail: [email protected]
>>> <mailto:[email protected]>
>>> <mailto:[email protected]>
>>> For additional commands, e-mail: [email protected]
>>> <mailto:[email protected]>
>>> <mailto:[email protected]>
>> --
>> Jim
>> "This is an outrage!"
>> Tony Harrison
>>
>>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> <mailto:[email protected]>
> For additional commands, e-mail: [email protected]
> <mailto:[email protected]>
--
Jim
"This is an outrage!"
Tony Harrison