Public signed DMG release
The local self-signed certificate is for development. Public downloads require a Developer ID Application certificate, its private key, an Apple notarization submission, and stapled tickets. This allows Gatekeeper to verify the app; it is not a guarantee that every company security policy will allow it, and Screen Recording/Microphone/Speech permissions are still required. See Apple's Developer ID instructions and notarization workflow.
Give the release process access without sending a key in chat
- Enroll in the Apple Developer Program, or use the team's existing account. Apple requires the Account Holder to create a downloadable Developer ID certificate; use your existing valid identity if available.
- On this Mac, open Keychain Access → Certificate Assistant → Request a Certificate From a Certificate Authority. Save the CSR to disk. The matching private key stays in Keychain.
- In Certificates, Identifiers & Profiles, add Developer ID Application, upload the CSR, and download the
.cer. Do not choose Developer ID Installer; this release contains an app inside a DMG, not a.pkginstaller. - Double-click the
.ceron the same Mac. In Keychain Access, check that the certificate expands to show its private key. If the identity was created on another Mac, securely export/import the certificate and private key as an encrypted.p12, keeping it outside this repository. Do not paste the key or password into chat. - Run
security find-identity -v -p codesigningand give the agent only the public 40-character SHA-1 fingerprint and Team ID. The agent can sign using the installed Keychain identity; no private-key upload is needed. - Create an Apple ID app-specific password in your Apple account. In your terminal, run
xcrun notarytool store-credentials klicksea-notaryand enter your Apple ID, Team ID, and app-specific password when prompted. These credentials stay in Keychain. Tell the agent the profile nameklicksea-notary, not the password. A notary API-key profile is also supported if your team uses one. - If macOS asks whether codesign can use this key, approve it in the system dialog. Keep an encrypted private-key backup and use the same team identity for subsequent releases.
This does not replace .signing.env or the local development signing state. The distribution script stages a separate release bundle so development permission identity does not silently change.
Build and notarize
Set the public fingerprint and profile name in your terminal:
export DEVELOPER_ID_APPLICATION_SHA1="YOUR_40_CHARACTER_SHA1"
export NOTARY_PROFILE=klicksea-notary
bash scripts/release-dmg.shThe script builds Apple silicon and Intel slices, combines them, signs with Hardened Runtime and a secure timestamp, notarizes/staples the app, creates a DMG with an Applications shortcut, signs/notarizes/staples the DMG, assesses Gatekeeper, and writes SHA-256 checksums under dist/release/. It refuses local/self-signed identities. It has not been exercised with Developer ID credentials yet; a downloaded install on another Mac remains required.
Publish after verifying on another Mac
Set the version in Resources/Info.plist, run the manual acceptance checks and release script, then:
gh release create v0.1.0 \
dist/release/KlickSea-0.1.0-universal.dmg \
dist/release/KlickSea-0.1.0-universal.dmg.sha256 \
--repo techsavvyash/klicksea --title 'KlickSea 0.1.0' --notes-file RELEASE_NOTES.mdCreate RELEASE_NOTES.md describing actual tested behavior and known limits. Do not publish the development bundle as a trusted download. The public landing page should link to Releases until a verified DMG is available.