Skip to content

Release signed and notarized standalone CLI, app, and combined artifacts #17

Description

@jordancalhoun

Summary

Extend the existing publish-script workflow to generate and publish standalone Swiftpkg CLI and Swiftpkgr app releases in addition to a combined installer. Every distributed artifact must be signed and notarized.

Release artifacts

The workflow should produce:

  1. Swiftpkgr app archive

    • A .zip containing Swiftpkgr.app.
    • The app is Developer ID signed before archiving.
    • The ZIP is submitted for notarization and stapling is applied to the app before the final archive is produced.
  2. Combined installer

    • A signed installer package containing both the swiftpkg CLI and Swiftpkgr.app.
    • The installer is notarized and stapled.
  3. CLI-only installer

    • A signed installer package containing only the swiftpkg command-line tool.
    • The installer is notarized and stapled.

Implementation requirements

  • Build all artifacts through the existing scripts/publish-xcode-release.sh workflow rather than introducing a separate release path.
  • Preserve the current Universal release architecture and existing version-source checks.
  • Use consistent versioned filenames that clearly distinguish the app archive, combined installer, and CLI-only installer.
  • Sign nested code in the correct order and verify signatures before notarization.
  • Submit each distributable artifact for notarization, wait for completion, and fail with actionable diagnostics when notarization is rejected.
  • Staple notarization tickets wherever the artifact format supports stapling, then verify the final deliverables.
  • Generate checksums for every published artifact.
  • Include all artifacts and checksums in the GitHub Release when publishing is enabled.
  • Preserve the existing unsigned/local development mode where applicable, with clear behavior for artifacts that cannot be notarized unsigned.
  • Clean up temporary packaging products without deleting final release artifacts.

Acceptance criteria

  • A successful signed release produces a notarized Swiftpkgr app ZIP, notarized combined installer, and notarized CLI-only installer.
  • The app ZIP expands to a signed and notarized Swiftpkgr.app that passes Gatekeeper assessment.
  • Both installer packages pass signature verification, Gatekeeper assessment, and stapler validation.
  • The combined installer installs both the CLI and app into their documented locations.
  • The CLI-only installer installs no Swiftpkgr app payload.
  • Release filenames and generated checksums are deterministic and suitable for GitHub Releases and downstream automation.
  • A failure in building, signing, notarizing, stapling, or verifying any required artifact stops publication with an actionable error.
  • The workflow remains runnable through the existing publish script entry point.

Documentation

  • Document the artifact matrix and intended use of each download.
  • Document required signing identities and notary profile configuration without placing credentials in the repository.
  • Update release instructions and GitHub Release notes/templates to identify the standalone and combined downloads.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions