Unless things have changed signing with ASF credentials is not free. If 
continuing with Peter’s plan then a distinction needs to be made between 
signing a developer’s or ci build, and signing a release build.

> On Sep 10, 2026, at 4:24 AM, Jim Jagielski <[email protected]> wrote:
> 
> Whatever you want. I'm done.
> 
>> On Sep 10, 2026, at 6:54 AM, Peter Kovacs <[email protected]> wrote:
>> 
>> 
>> 
>> Am 10. September 2026 12:24:19 MESZ schrieb Jim Jagielski <[email protected] 
>> <mailto:[email protected]>>:
>>> On our builds, yes of course. But we should not force someone who downloads 
>>> the source and builds for themselves to also sign that.
>>> 
>>> Traditionally, we've always signed after we build as a separate process 
>>> from building the community build DMGs.
>>> 
>>> Hopefully that's a bit more clear :) 
>> Ok. And what solution do you propose?
>> Apple says packaging involves signing. You can not change that.
>> I am for we release proper signed software or none at all. There is no in 
>> between anymore. 
>>> 
>>>> On Sep 10, 2026, at 5:59 AM, Peter Kovacs <[email protected]> wrote:
>>>> 
>>>> 
>>>> 
>>>> Am 10. September 2026 11:47:21 MESZ schrieb Jim Jagielski 
>>>> <[email protected]>:
>>>>> I can't imagine the regular user wanting/needing to sign...
>>>> Sorry maybe I was not clear.
>>>> I think we should enforce signing on all builds.
>>>> The user can always see if that build is from us or someone else. 
>>>> Development builds will always trigger the gatekeeper.
>>>>> 
>>>>>> On Sep 10, 2026, at 5:38 AM, Peter Kovacs <[email protected]> wrote:
>>>>>> 
>>>>>> 
>>>>>> 
>>>>>> Am 10. September 2026 11:30:18 MESZ schrieb Jim Jagielski 
>>>>>> <[email protected] <mailto:[email protected]>>:
>>>>>>> I am also wondering if the actual signing script itself should be in 
>>>>>>> devtools, somewhere under release-scripts instead.
>>>>>> 
>>>>>> The process ist to sign the app, then package the image, and then you 
>>>>>> need to sign again.
>>>>>> 
>>>>>> I would rather enforce signing to be mandatory.
>>>>>> What we could put into Devtools maybe is the notarize of the installer. 
>>>>>> Which publishes the release at Apple. I guess. And then we could think 
>>>>>> about a process to publish in the store.
>>>>>>> 
>>>>>>> Cool work.
>>>>>> Yes. I hope this will
>>>>>>> 
>>>>>>>> On Sep 10, 2026, at 5:14 AM, Jim Jagielski <[email protected]> wrote:
>>>>>>>> 
>>>>>>>> Is there any way you could pull out just the signing bits into a 
>>>>>>>> separate commit?
>>>>>>>> 
>>>>>>>>> On Sep 10, 2026, at 12:26 AM, [email protected] wrote:
>>>>>>>>> 
>>>>>>>>> 
>>>>>>> 
>>>>>>> --
>>>>>>> Jim
>>>>>>> "This is an outrage!"
>>>>>>>                    Tony Harrison
>>>>>>> 
>>>>>> 
>>>>>> ---------------------------------------------------------------------
>>>>>> To unsubscribe, e-mail: [email protected] 
>>>>>> <mailto:[email protected]>
>>>>>> For additional commands, e-mail: [email protected] 
>>>>>> <mailto:[email protected]>
>>>>> --
>>>>> Jim
>>>>> "This is an outrage!"
>>>>>                     Tony Harrison
>>>>> 
>>>> 
>>>> ---------------------------------------------------------------------
>>>> To unsubscribe, e-mail: [email protected]
>>>> For additional commands, e-mail: [email protected]
>>>> 
>>> 
>>> --
>>> Jim
>>> "This is an outrage!"
>>>                      Tony Harrison
>>> 
>> 
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: [email protected] 
>> <mailto:[email protected]>
>> For additional commands, e-mail: [email protected] 
>> <mailto:[email protected]>
> --
> Jim
>  "This is an outrage!"
>                        Tony Harrison
> 


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to