macOS DMG Builder
Overview
Use this skill to create a repeatable macOS release pipeline with signed and notarized .app and .dmg artifacts.
Prefer existing project scripts first. If the project does not already have release automation, scaffold it from assets/templates/ using the bundled script.
Onboarding Walkthrough (Mandatory)
Before running release commands, collect or confirm these values. Do not skip this step.
repo_root(absolute path to target repo)app_name(display name of the app in Finder/DMG)xcode_scheme(build/archive scheme)bundle_id(for entitlement/signing sanity checks)artifact_dir(where.appand.dmgshould be written)team_id(Apple Developer Team ID)apple_id(Apple ID used for notarization)notary_profile(Keychain profile name fornotarytool)signing_identitypreference (display name or SHA-1 hash)
If any required value is missing, ask focused questions before proceeding. Use defaults only when they are verifiably correct for the repo.
Onboarding defaults for LemonNotes:
repo_root:/Users/jakerains/Projects/LemonNotesapp_name:LemonNotesxcode_scheme:LemonNotesMacartifact_dir:macos/.release/outputteam_id:47347VQHQVnotary_profile:LemonNotesApp-Notarize
Run preflight checks immediately after onboarding:
scripts/preflight_release_env.sh --profile <notary-profile>
Workflow
1) Detect existing release automation
- Check for
scripts/macos-release.sh. - Check for
scripts/macos-notary-setup.sh. - Check
Makefileformacos-releaseandmacos-notary-setuptargets.
2) If missing, scaffold release automation
- Run
scripts/scaffold_release_pipeline.sh --repo <repo-root>. - Add
--apply-makefileto append targets automatically. - Add
--forceonly when replacing existing scripts intentionally.
3) Configure notary profile (one-time per machine/profile)
- Run
scripts/setup_notary_profile.sh. - Default profile for LemonNotes is
LemonNotesApp-Notarize. - Use app-specific password input securely (prompt or env var) and never print it in output.
4) Run release
- Run
make macos-releasefrom repo root. - Confirm phases:
- archive
- app notarization/stapling
- DMG creation/signing
- DMG notarization/stapling
5) Verify and report
- Run
scripts/verify_release_artifacts.sh. - Report:
- output paths
- notarization/staple validation status
- SHA256 of DMG
Credential and Security Rules
- Never echo app-specific passwords to terminal output.
- Prefer prompting interactively for secrets.
- If a user shares a password in chat, use it only for immediate setup and avoid repeating it.
- Prefer app-specific notary profiles (e.g.,
LemonNotesApp-Notarize) over reusing unrelated profile names.
Troubleshooting Quick Fixes
- Duplicate Developer ID name ambiguity:
- Resolve to SHA-1 with
security find-identity -v -p codesigning. - Sign with hash identity, not display name.
- Resolve to SHA-1 with
- Profile not found:
- Run
scripts/check_notary_profile.sh <profile>. - Run
scripts/setup_notary_profile.shif missing.
- Run
- Release script exits unexpectedly:
- Re-run with tracing:
bash -x scripts/macos-release.sh. - Continue from first failing phase.
- Re-run with tracing:
LemonNotes Quick Path
- Run onboarding checklist from
references/onboarding-playbook.md. - Run
make macos-notary-setup. - Run
make macos-release. - Expect artifacts in
macos/.release/output.
Read references/lemonnotes-integration.md for exact LemonNotes defaults and conventions.
Resources
scripts/inspect_signing_identities.sh: list usable Developer ID identities and suggested exports.scripts/preflight_release_env.sh: preflight check for tools, certs, and optional notary profile.scripts/check_notary_profile.sh: validate a notary profile from Keychain.scripts/setup_notary_profile.sh: create/update notary profile credentials.scripts/scaffold_release_pipeline.sh: install release/notary scripts into a repo.scripts/verify_release_artifacts.sh: validate signatures/staples and print DMG hash.references/onboarding-playbook.md: onboarding interview + zero-to-release checklist.references/workflow.md: generic release flow and checks.references/lemonnotes-integration.md: LemonNotes-specific defaults.assets/templates/: template scripts and Makefile snippet.
微信扫一扫