feat: enable macOS code signing and notarization in release workflow - #2
Conversation
Adds hardened runtime + Developer ID env vars for tauri-action so release builds get signed and notarized on macOS.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughThe Tauri macOS bundle enables hardened runtime and requires macOS 10.15. The release workflow separates macOS builds from other platforms and supplies Apple signing credentials to the macOS build. ChangesmacOS signing configuration
Estimated code review effort: 2 (Simple) | ~5 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Warning Review ran into problems🔥 ProblemsGit: Failed to clone repository. Please run the Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 54-59: Scope the Apple credential environment variables in the
release workflow to macOS matrix jobs only. Update the release job or step
containing APPLE_CERTIFICATE, APPLE_CERTIFICATE_PASSWORD,
APPLE_SIGNING_IDENTITY, APPLE_ID, APPLE_PASSWORD, and APPLE_TEAM_ID so Ubuntu
and Windows runners do not receive these secrets, while preserving their
availability for macOS releases.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 9b273cad-b8ff-4e3e-8250-84509794c262
📒 Files selected for processing (2)
.github/workflows/release.ymlsrc-tauri/tauri.conf.json
…roved platform handling
What this changes
Adds hardened runtime + Developer ID env vars for tauri-action so release builds get signed and notarized on macOS.
Checklist
npm run tauri devand tried the change locallycargo testinsrc-tauriand everything passescargo fmtandcargo clippyon Rust changesSummary by CodeRabbit