Skip to content

Fix macOS notarization to use the current signing identity's team - #652

Merged
danoli3 merged 2 commits into
openframeworks:masterfrom
danoli3:fix-macos-notarization-team-id
Sep 14, 2026
Merged

danoli3 merged 2 commits into
openframeworks:masterfrom
danoli3:fix-macos-notarization-team-id

Conversation

@danoli3

@danoli3 danoli3 commented Sep 14, 2026 •

Copy link
Copy Markdown
Member

Fixes Notarization

Rotates the expired Developer ID Application certificate and fixes notarization by removing the hardcoded previous Team ID/Apple ID. Notarization now uses an App Store Connect API key (APPLE_API_KEY_P8, APPLE_API_KEY_ID, APPLE_API_ISSUER_ID), decoupling CI from individual Apple accounts.

Fixes: #646

CERTIFICATE_OSX_APPLICATION was rotated to a new Developer ID
Application certificate (the previous one expired, see openframeworks#646), but
ci_build_pg.sh still hardcoded the old certificate holder's Team ID
and Apple ID for xcrun notarytool. Since notarization requires
--team-id to match the team that issued the signing certificate, this
would have submitted a build signed under one identity's team while
authenticating as a different one, and notarization would fail.

Reads TEAM_ID from a new CERTIFCATE_TEAM_ID secret and APPLE_ID from
the already-updated GA_APPLE_USERNAME secret instead, in both the
active package_app() path and the unreachable-but-should-stay-
consistent sign_and_upload() path.
Apple ID + app-specific password ties CI notarization to a personal
account's credentials, which need re-issuing every time the account
holder changes (as just happened rotating away from the expired
Theo Watson certificate). An App Store Connect API key is decoupled
from any individual Apple ID, scoped to just the Developer role, and
revocable independently of anyone's personal account.

Adds setup_notarization_key(), which writes the raw .p8 key contents
(APPLE_API_KEY_P8 - GitHub secrets preserve multi-line values as-is,
so no base64 step is needed) to a file for notarytool's --key flag,
and switches both notarytool submit call sites from
--apple-id/--team-id/--password to --key/--key-id/--issuer.

GA_APPLE_USERNAME/GA_APPLE_PASS/CERTIFCATE_TEAM_ID are no longer read
by any active code path after this - left as-is in the workflow env
block rather than removed, since deleting secrets/wiring wasn't the
point of this change.
@danoli3
danoli3 merged commit 2a2dcec into openframeworks:master Sep 14, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

PG: macOS Signing certificate expired

1 participant