Skip to content

feat: enable macOS code signing and notarization in release workflow - #2

Merged
t0bx merged 2 commits into
mainfrom
feat/macos-signing-setup
Jul 20, 2026
Merged

t0bx merged 2 commits into
mainfrom
feat/macos-signing-setup

Conversation

@t0bx

@t0bx t0bx commented Jul 20, 2026 •

Copy link
Copy Markdown
Owner

What this changes

Adds hardened runtime + Developer ID env vars for tauri-action so release builds get signed and notarized on macOS.

Checklist

  • I ran npm run tauri dev and tried the change locally
  • I ran cargo test in src-tauri and everything passes
  • I ran cargo fmt and cargo clippy on Rust changes
  • I updated the README/docs if behavior or config changed
  • No unrelated changes snuck in

Summary by CodeRabbit

  • New Features
    • Improved the macOS release process by enabling conditional Apple signing with required credentials.
    • Added macOS hardened runtime protection.
    • Set the minimum supported macOS version to 10.15 for bundled apps.
    • Kept release behavior for non-macOS platforms unchanged.

Adds hardened runtime + Developer ID env vars for tauri-action so
release builds get signed and notarized on macOS.
@t0bx t0bx self-assigned this Jul 20, 2026
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: ff6268fc-c8e8-4171-8582-cdc1382c9d1a

📥 Commits

Reviewing files that changed from the base of the PR and between 76d6981 and 16311c1.

📒 Files selected for processing (1)
  • .github/workflows/release.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/release.yml

📝 Walkthrough

Walkthrough

The Tauri macOS bundle enables hardened runtime and requires macOS 10.15. The release workflow separates macOS builds from other platforms and supplies Apple signing credentials to the macOS build.

Changes

macOS signing configuration

Layer / File(s) Summary
Configure macOS release signing
src-tauri/tauri.conf.json, .github/workflows/release.yml
The bundle enables hardened runtime with macOS 10.15 as the minimum version, while the macOS release step receives Apple signing credentials and identifiers from secrets.

Estimated code review effort: 2 (Simple) | ~5 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main change: enabling macOS code signing and notarization in the release workflow.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/macos-signing-setup

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/release.yml:
- Around line 54-59: Scope the Apple credential environment variables in the
release workflow to macOS matrix jobs only. Update the release job or step
containing APPLE_CERTIFICATE, APPLE_CERTIFICATE_PASSWORD,
APPLE_SIGNING_IDENTITY, APPLE_ID, APPLE_PASSWORD, and APPLE_TEAM_ID so Ubuntu
and Windows runners do not receive these secrets, while preserving their
availability for macOS releases.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 9b273cad-b8ff-4e3e-8250-84509794c262

📥 Commits

Reviewing files that changed from the base of the PR and between 42ae785 and 76d6981.

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • src-tauri/tauri.conf.json

Comment thread .github/workflows/release.yml
@t0bx
t0bx merged commit fda509d into main Jul 20, 2026
3 checks passed
@t0bx
t0bx deleted the feat/macos-signing-setup branch July 20, 2026 09:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant