Fix the notarization zip step: ditto -c takes exactly one source - #122
Merged
Merged
Conversation
Found by actually running the pipeline locally end to end: built st/pt,
packaged both into app bundles, signed them with the dedicated Developer
ID Application certificate, and hit this at the submission-zip step
before ever reaching Apple.
`ditto -c` takes exactly one source ("Can't archive multiple sources") -
--keepParent does not turn it into a multi-source flag. Stage both apps
under one directory first and archive that instead.
With the fix, the rest of the pipeline ran clean against Apple's real
services: notarytool submission came back "Accepted", both bundles
stapled and validated, and spctl reports "accepted / source=Notarized
Developer ID" on both - including with the quarantine xattr set, which
is what actually happens to a browser download and is the dialog this
whole pipeline exists to prevent.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #122 +/- ##
=======================================
Coverage 89.19% 89.19%
=======================================
Files 81 81
Lines 19898 19898
Branches 4751 4751
=======================================
+ Hits 17748 17749 +1
+ Misses 951 950 -1
Partials 1199 1199 see 6 files with indirect coverage changes
🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #120, which merged before this fix landed.
The bug
The notarize step builds its submission archive with
but
ditto -caccepts exactly one source: it fails withCan't archive multiple sources.--keepParentdoes not change that. The command was written on the assumption that it behaves likecp, and was never run until now.Why it matters right now
With the signing and notarization secrets set on this repo, a Release run would sign both bundles, then fail here, and
package-releaseneedssign-notarize-darwin, so no release would be published. Before the secrets existed this step skipped gracefully with a warning, so this only bites now.The fix
Stage both apps under one directory and archive that single directory. One file, +10/-1.
Verified
Found by running the pipeline locally end to end, and re-checked with the exact zip layout this produces:
notarytool submitreturnedAcceptedfor the bundles signed with the Developer ID certificate, and again with the dedicated App Store Connect key now stored in this repo's secrets, so the credential and the archive shape are both proven against Apple.spctl -a -vv -t executereportsaccepted / source=Notarized Developer ID, including with the quarantine xattr set.master;actionlintreports nothing beyond this file's existing findings.Please merge this before triggering the next Release run.
🤖 Generated with Claude Code