Summary
Extend the existing publish-script workflow to generate and publish standalone Swiftpkg CLI and Swiftpkgr app releases in addition to a combined installer. Every distributed artifact must be signed and notarized.
Release artifacts
The workflow should produce:
-
Swiftpkgr app archive
- A
.zip containing Swiftpkgr.app.
- The app is Developer ID signed before archiving.
- The ZIP is submitted for notarization and stapling is applied to the app before the final archive is produced.
-
Combined installer
- A signed installer package containing both the
swiftpkg CLI and Swiftpkgr.app.
- The installer is notarized and stapled.
-
CLI-only installer
- A signed installer package containing only the
swiftpkg command-line tool.
- The installer is notarized and stapled.
Implementation requirements
- Build all artifacts through the existing
scripts/publish-xcode-release.sh workflow rather than introducing a separate release path.
- Preserve the current Universal release architecture and existing version-source checks.
- Use consistent versioned filenames that clearly distinguish the app archive, combined installer, and CLI-only installer.
- Sign nested code in the correct order and verify signatures before notarization.
- Submit each distributable artifact for notarization, wait for completion, and fail with actionable diagnostics when notarization is rejected.
- Staple notarization tickets wherever the artifact format supports stapling, then verify the final deliverables.
- Generate checksums for every published artifact.
- Include all artifacts and checksums in the GitHub Release when publishing is enabled.
- Preserve the existing unsigned/local development mode where applicable, with clear behavior for artifacts that cannot be notarized unsigned.
- Clean up temporary packaging products without deleting final release artifacts.
Acceptance criteria
- A successful signed release produces a notarized Swiftpkgr app ZIP, notarized combined installer, and notarized CLI-only installer.
- The app ZIP expands to a signed and notarized
Swiftpkgr.app that passes Gatekeeper assessment.
- Both installer packages pass signature verification, Gatekeeper assessment, and stapler validation.
- The combined installer installs both the CLI and app into their documented locations.
- The CLI-only installer installs no Swiftpkgr app payload.
- Release filenames and generated checksums are deterministic and suitable for GitHub Releases and downstream automation.
- A failure in building, signing, notarizing, stapling, or verifying any required artifact stops publication with an actionable error.
- The workflow remains runnable through the existing publish script entry point.
Documentation
- Document the artifact matrix and intended use of each download.
- Document required signing identities and notary profile configuration without placing credentials in the repository.
- Update release instructions and GitHub Release notes/templates to identify the standalone and combined downloads.
Summary
Extend the existing publish-script workflow to generate and publish standalone Swiftpkg CLI and Swiftpkgr app releases in addition to a combined installer. Every distributed artifact must be signed and notarized.
Release artifacts
The workflow should produce:
Swiftpkgr app archive
.zipcontainingSwiftpkgr.app.Combined installer
swiftpkgCLI andSwiftpkgr.app.CLI-only installer
swiftpkgcommand-line tool.Implementation requirements
scripts/publish-xcode-release.shworkflow rather than introducing a separate release path.Acceptance criteria
Swiftpkgr.appthat passes Gatekeeper assessment.Documentation