Move JPDFium dylib signing step AFTER cert import

My first placement put the sign-jpdfium-dylibs-in-bootjar step at
the wrong point in the workflow: BEFORE the "Verify Certificate"
step that sets APPLE_SIGNING_IDENTITY in GITHUB_ENV. So the gate
`if: ... && env.APPLE_SIGNING_IDENTITY != ''` always evaluated to
false and the step silently skipped, leaving the dylibs unsigned
and notarytool still rejecting the .app.

Move it to right after Verify Certificate (which sets the env var
from the keychain identity). Also switch the gate to checking
env.APPLE_CERTIFICATE (the secret that's set at job level and
available from step 1) rather than env.APPLE_SIGNING_IDENTITY (set
mid-workflow via GITHUB_ENV) — the latter is fine in `run:` blocks
but flaky in `if:` evaluation depending on GH Actions evaluation
timing.
This commit is contained in:
Anthony Stirling
2026-05-20 09:08:37 +01:00
parent 9458fcd0e2
commit 2a151b65f7
+11 -15
View File
@@ -158,21 +158,6 @@ jobs:
MAVEN_PUBLIC_URL: ${{ secrets.MAVEN_PUBLIC_URL }}
DISABLE_ADDITIONAL_FEATURES: true
- name: Sign JPDFium dylibs inside bootJar (macOS only)
# JPDFium's publish workflow has no Apple Developer credentials, so
# the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned.
# Apple's notarytool walks into nested .jars inside the .app and
# rejects unsigned binaries. Tauri's own codesign walk doesn't open
# .jars, so we have to re-sign them here, between bootJar build and
# tauri-action, using this build's Developer ID identity. The script
# is non-fatal: if APPLE_SIGNING_IDENTITY isn't set (e.g. PR build
# from a fork) it exits 0 and notarytool will continue to report
# the unsigned-binary error.
if: matrix.platform == 'macos-15' && env.APPLE_SIGNING_IDENTITY != ''
env:
APPLE_SIGNING_IDENTITY: ${{ env.APPLE_SIGNING_IDENTITY }}
run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh
# DigiCert KeyLocker Setup (Cloud HSM)
- name: Setup DigiCert KeyLocker
id: digicert-setup
@@ -284,6 +269,17 @@ jobs:
echo "APPLE_SIGNING_IDENTITY=$CERT_ID" >> $GITHUB_ENV
echo "Certificate imported successfully."
- name: Sign JPDFium dylibs inside bootJar (macOS only)
# JPDFium's publish workflow has no Apple Developer credentials, so
# the .dylibs it ships in jpdfium-natives-darwin-*.jar are unsigned.
# Apple's notarytool walks into nested .jars inside the .app and
# rejects unsigned binaries. Tauri's own codesign walk doesn't open
# .jars, so we have to re-sign them here, between cert import and
# tauri-action, using this build's Developer ID identity (set in
# GITHUB_ENV by the Verify Certificate step above).
if: matrix.platform == 'macos-15' && env.APPLE_CERTIFICATE != ''
run: bash scripts/sign-jpdfium-dylibs-in-bootjar.sh
- name: Check DMG creation dependencies (macOS only)
if: matrix.platform == 'macos-15'
run: |