Repository navigation
Fix macOS notarization to use the current signing identity's team - #652
Merged
danoli3 merged 2 commits intoSep 14, 2026
Merged
Conversation
CERTIFICATE_OSX_APPLICATION was rotated to a new Developer ID Application certificate (the previous one expired, see openframeworks#646), but ci_build_pg.sh still hardcoded the old certificate holder's Team ID and Apple ID for xcrun notarytool. Since notarization requires --team-id to match the team that issued the signing certificate, this would have submitted a build signed under one identity's team while authenticating as a different one, and notarization would fail. Reads TEAM_ID from a new CERTIFCATE_TEAM_ID secret and APPLE_ID from the already-updated GA_APPLE_USERNAME secret instead, in both the active package_app() path and the unreachable-but-should-stay- consistent sign_and_upload() path.
Apple ID + app-specific password ties CI notarization to a personal account's credentials, which need re-issuing every time the account holder changes (as just happened rotating away from the expired Theo Watson certificate). An App Store Connect API key is decoupled from any individual Apple ID, scoped to just the Developer role, and revocable independently of anyone's personal account. Adds setup_notarization_key(), which writes the raw .p8 key contents (APPLE_API_KEY_P8 - GitHub secrets preserve multi-line values as-is, so no base64 step is needed) to a file for notarytool's --key flag, and switches both notarytool submit call sites from --apple-id/--team-id/--password to --key/--key-id/--issuer. GA_APPLE_USERNAME/GA_APPLE_PASS/CERTIFCATE_TEAM_ID are no longer read by any active code path after this - left as-is in the workflow env block rather than removed, since deleting secrets/wiring wasn't the point of this change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes Notarization
Rotates the expired Developer ID Application certificate and fixes notarization by removing the hardcoded previous Team ID/Apple ID. Notarization now uses an App Store Connect API key (APPLE_API_KEY_P8, APPLE_API_KEY_ID, APPLE_API_ISSUER_ID), decoupling CI from individual Apple accounts.
Fixes: #646