From 2174aa36db2041eb5fc2f168a94b8899ae737ff6 Mon Sep 17 00:00:00 2001 From: Alvin Unreal Date: Wed, 20 May 2026 21:56:39 +0200 Subject: [PATCH] Fix macOS desktop release packaging --- apps/desktop/electron-builder.yml | 5 ++++- apps/desktop/package.json | 2 +- apps/desktop/scripts/release-local.mjs | 30 +++++++++----------------- docs/release.md | 28 +++++++++++++++++++++++- 4 files changed, 42 insertions(+), 23 deletions(-) diff --git a/apps/desktop/electron-builder.yml b/apps/desktop/electron-builder.yml index 7d8d0211..cfb66f0e 100644 --- a/apps/desktop/electron-builder.yml +++ b/apps/desktop/electron-builder.yml @@ -31,7 +31,10 @@ mac: target: - dmg - zip - identity: null + # Ad-hoc sign macOS bundles when a Developer ID certificate is unavailable. + # Leaving the app bundle fully unsigned can produce Gatekeeper's misleading + # "damaged and can't be opened" dialog on Apple Silicon releases. + identity: "-" hardenedRuntime: false gatekeeperAssess: false diff --git a/apps/desktop/package.json b/apps/desktop/package.json index a2dea05b..70d02856 100644 --- a/apps/desktop/package.json +++ b/apps/desktop/package.json @@ -1,6 +1,6 @@ { "name": "@open-pets/desktop", - "version": "2.1.0", + "version": "2.1.1", "private": true, "description": "OpenPets tray-first desktop companion app.", "license": "MIT", diff --git a/apps/desktop/scripts/release-local.mjs b/apps/desktop/scripts/release-local.mjs index f84ca51f..b6c474c5 100644 --- a/apps/desktop/scripts/release-local.mjs +++ b/apps/desktop/scripts/release-local.mjs @@ -208,38 +208,28 @@ function run(command, args, options) { function defaultReleaseNotes() { return [ - `OpenPets ${tag} introduces first-party desktop plugins.`, + `OpenPets ${tag} is a desktop packaging patch for macOS users.`, "", - "## New: OpenPets Plugins", + "## Fixed", "", - "OpenPets now includes a first-party plugin platform for optional desktop companion behaviors.", + "- Fixed macOS release packaging so app bundles are ad-hoc signed when a Developer ID certificate is unavailable.", + "- This addresses the misleading macOS Gatekeeper dialog that can say OpenPets is damaged and can't be opened on Apple Silicon/Sequoia.", + "- Rebuilt desktop artifacts with optional packages included: macOS ZIP, Windows portable, Linux DEB/RPM, and Linux tar.gz.", "", - "### Included plugins", + "## Still included from v2.1.0", "", "- Daily Reminders — recurring local reminders with custom messages, reactions, days, and intervals.", "- Pomodoro — focus and break sessions with pet feedback and controls.", "- GitHub Notifications — public repository release and failed-workflow notifications. No GitHub login, token, or private repository access is used.", "", - "### Plugin management", - "", - "- New polished Plugins window with install, enable, configure, update, reload, and uninstall actions.", - "- Friendly plugin configuration UI; no JSON editing required.", - "- Plugin permissions and network hosts are explicit.", - "- JavaScript plugins run in a sandboxed renderer with a narrow OpenPets SDK.", - "", - "### Developer notes", - "", - "- Local plugin development is available through explicit developer mode and `pnpm dev:desktop:plugins`.", - "- Legacy sample plugins were removed from discovery.", - "", - "### Known limitations", + "## Known limitations", "", "- GitHub Notifications supports public repositories only in this release.", - "- Desktop artifacts are currently unsigned, so OS security warnings may appear.", + "- macOS artifacts are ad-hoc signed but not Developer ID notarized yet, so Gatekeeper may still require a first-open confirmation.", + "- Windows artifacts are unsigned, so SmartScreen warnings may appear.", "", "After publishing:", - "- Smoke test macOS, Windows, and Linux artifacts.", - "- Expect Gatekeeper/SmartScreen warnings until signing/notarization is configured.", + "- Smoke test macOS DMG/ZIP, Windows installer/portable, and Linux artifacts.", ].join("\n"); } diff --git a/docs/release.md b/docs/release.md index 0d50e70f..7976e98a 100644 --- a/docs/release.md +++ b/docs/release.md @@ -10,7 +10,33 @@ This guide is for an AI agent creating a new OpenPets desktop release from a loc - Root command: `pnpm release:desktop` - Update checker expects GitHub release tags like `v2.0.0`. -## Current plugin platform release plan +## Current desktop patch release plan + +The next end-user release is a **desktop-only macOS packaging patch** for issue #30. Do **not** publish npm packages for this patch. + +Release goals: + +1. Ship a new desktop GitHub Release with `apps/desktop/package.json` bumped to the next patch version. +2. Build with optional desktop artifacts included via `pnpm release:desktop -- --yes --include-optional`. +3. Keep npm packages unchanged because this is an Electron packaging/release artifact fix only. +4. Confirm the macOS app bundle passes local `codesign --verify --deep --strict` before publishing. + +Suggested patch release notes: + +```md +## Fixed + +- Fixed macOS release packaging so app bundles are ad-hoc signed when a Developer ID certificate is unavailable. +- This addresses the misleading macOS Gatekeeper dialog that can say OpenPets is damaged and can't be opened on Apple Silicon/Sequoia. +- Rebuilt desktop artifacts with optional packages included: macOS ZIP, Windows portable, Linux DEB/RPM, and Linux tar.gz. + +## Known limitations + +- macOS artifacts are ad-hoc signed but not Developer ID notarized yet, so Gatekeeper may still require a first-open confirmation. +- Windows artifacts are unsigned, so SmartScreen warnings may appear. +``` + +## Previous plugin platform release plan The next end-user release is a **desktop + web plugin catalog release**, not an npm package release by default.