From 1a87ceae6331fa90b5eaa4241eeec901899fc15d Mon Sep 17 00:00:00 2001 From: Brad King Date: Sun, 14 Dec 2025 16:14:07 -0500 Subject: [PATCH] Utilities/Release: Teach macOS signing script to use custom keychain --- Utilities/Release/macos/sign-notarize.bash | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/Utilities/Release/macos/sign-notarize.bash b/Utilities/Release/macos/sign-notarize.bash index 52aa60d382..169f5f8f97 100755 --- a/Utilities/Release/macos/sign-notarize.bash +++ b/Utilities/Release/macos/sign-notarize.bash @@ -9,11 +9,13 @@ Options: -id Signing Identity -kp Keychain profile containing notarization credentials. + -kc Keychain path containing named profile. Create the keychain profile ahead of time using xcrun notarytool store-credentials \ - --apple-id --team-id [--password ] + --apple-id --team-id \ + [--keychain ] [--password ] where: @@ -42,10 +44,12 @@ die() { } id='' +keychain='' keychain_profile='' while test "$#" != 0; do case "$1" in -id|-i) shift; id="$1" ;; + -kc|--keychain) shift; keychain="$1" ;; -kp|-k|--keychain-profile) shift; keychain_profile="$1" ;; --) shift ; break ;; -*) die "$usage" ;; @@ -107,7 +111,15 @@ codesign --verify --timestamp --options=runtime --verbose --force \ ditto -c -k --keepParent "$vol_path/CMake.app" "$tmpdir/CMake.app.zip" # Notarize the application. -xcrun notarytool submit "$tmpdir/CMake.app.zip" --keychain-profile "$keychain_profile" --wait +notarize="xcrun notarytool submit '$tmpdir/CMake.app.zip'" +if test -n "$keychain_profile"; then + notarize="$notarize --keychain-profile '$keychain_profile'" + if test -n "$keychain"; then + notarize="$notarize --keychain '$keychain'" + fi +fi +notarize="$notarize --wait" +eval "$notarize" # Staple the notarization. xcrun stapler staple "$vol_path/CMake.app"