Releasing Brood (macOS)
This repo ships via GitHub Releases.
When you push a tag like v0.1.0, GitHub Actions will:
- run a remote macOS clean-machine smoke install (build DMG, install, launch)
- build a universal macOS app bundle
- stage the native Rust engine binary at
desktop/src-tauri/resources/brood-rs - code sign it (Developer ID Application)
- notarize it
- attach the signed/notarized
.dmgto a draft GitHub Release for that tag
Smoke details:
- Workflow:
.github/workflows/desktop-clean-machine-smoke.yml - Script:
scripts/macos_clean_machine_smoke.sh
One-Time Setup (GitHub Repo Secrets)
Set these secrets in your GitHub repository:
APPLE_CERTIFICATE: Base64-encoded.p12containing your Developer ID Application certificate.APPLE_CERTIFICATE_PASSWORD: Password for the.p12.APPLE_ID: Apple ID email used for notarization.APPLE_PASSWORD: App-specific password (or notarization password) forAPPLE_ID.APPLE_TEAM_ID: Your Apple Team ID (example:JU3DQ69K6R).BROOD_RELEASE_TOKEN(recommended): PAT used for GitHub Release create/upload calls inpublish.yml.- Use a token with repo contents write access (
reposcope for classic PAT, or equivalent fine-grained permission). - If omitted, workflow falls back to the default workflow token.
- Use a token with repo contents write access (
Notes:
- The workflow imports the certificate into a temporary build keychain and auto-detects the
Developer ID Applicationidentity to use. - Release staging signs
resources/brood-rswith hardened runtime + secure timestamp before notarization. - The workflow enforces
tag == v${tauri.conf.json package.version}to avoid accidental mismatches.
Cut A Release
- Update versions (must match):
desktop/package.jsonversiondesktop/src-tauri/tauri.conf.jsonpackage.versiondesktop/src-tauri/Cargo.toml[package].version
- Update
CHANGELOG.md. - Commit the changes.
- Tag and push:
git tag vX.Y.Zgit push origin vX.Y.Z
- Wait for the
publishworkflow to finish. - Publish the draft release on GitHub (or change
releaseDrafttofalsein the workflow once you're confident).
Optional: Disposable Remote Mac Snapshot Run
If you use a cloud Mac provider, keep one machine snapshot in a clean state and run:
git clone <repo-url>
cd brood
npm --prefix desktop ci
npm --prefix desktop run tauri build -- --bundles dmg --ci -v
scripts/macos_clean_machine_smoke.sh
Then discard/revert the snapshot. This gives repeatable install confidence without using multiple physical Macs.
Notarization Troubleshooting
If notarization fails with messages referencing Contents/Resources/resources/brood-rs (unsigned, missing timestamp, or no hardened runtime), confirm:
APPLE_SIGNING_IDENTITYis detected in the workflow.scripts/stage_rust_engine_binary.shran duringbeforeBuildCommand.- The release is built from a commit that includes the signing step for staged
brood-rs.