Skip to content

fix: sign and verify macOS beta binaries before packaging - #350

Merged
Obed0101 merged 1 commit into
mainfrom
fix/beta18-darwin-codesign
Sep 24, 2026
Merged

Obed0101 merged 1 commit into
mainfrom
fix/beta18-darwin-codesign

Conversation

@Obed0101

@Obed0101 Obed0101 commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Problem

v0.1.44-beta.17 shipped a Darwin arm64 executable with an invalid embedded Mach-O signature. macOS terminates it with SIGKILL (Code Signature Invalid), even though release checksum and attestation match.

Fix

Ad-hoc sign and strictly verify the compiled Darwin executable before smoke testing and archiving. Prepare beta.18 release notes. Keep the release provenance policy unchanged.

Validation

  • Native arm64 beta.18 build and startup (--version, --help)
  • Extracted Darwin arm64 ZIP: codesign --verify --strict and --version passed
  • node --test src/mendcode/script/release-index.test.mjs — 3 passed
  • git diff --check passed

After merge, dispatch release.yml from main with the merged SHA and validate published assets and provenance.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@Obed0101
Obed0101 merged commit 3792a1c into main Sep 24, 2026
8 checks passed
@Obed0101
Obed0101 deleted the fix/beta18-darwin-codesign branch September 24, 2026 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant