4 ms·
Glad to find out they notarized this. It isn't a .app though, which I think several in the thread are hoping to distribute outside the app store without making
by ziaddotcom 6y ago
Glad to find out they notarized this. It isn't a .app though, which I think several in the thread are hoping to distribute outside the app store without making it difficult/spooky for the end user.
If they notarized your prefpane/daemon combo, I suspect they would notarize quite a few .app applications that are properly signed and not malicious or frowned upon use cases.
- deergomoo 6y agoI was under the impression they would notarize essentially anything that doesn't match known malware? It's an automated system, not a manual review.
- ziaddotcom 6y agohttps://developer.apple.com/documentation/xcode/notarizing_macos_software_before_distribution https://developer.apple.com/documentation/xcode/notarizing_m... Anything that doesn't follow all the steps here wouldn't be notarized, I'm assuming. If a whatever.o file compiled from whatever.cpp with gcc from the command line wouldn't have any viable way of just being uploaded to a website for notarization. You'd have to at least go through all these steps. As far as I can tell, you'd need to have xcode to do that.
- user-the-name 6y ago.o files aren't notarised. Only the executable files that will be run by other people are.
- ziaddotcom 6y agoI suppose I could have wrote that a single .o file can be made an executable by gcc if the .o has a main function. Nearly any file can be set as an executable, and surely a bash script set to launch an un notarized app in your application folder wouldn't magically bypass the gatekeeper security prompt for that app.
- user-the-name 6y agoCommand line tools do not use notarisation at all.
- ziaddotcom 6y agohttps://scriptingosx.com/2019/09/notarize-a-command-line-tool/ https://scriptingosx.com/2019/09/notarize-a-command-line-too...
- user-the-name 6y agoQuoting that page, "Command Line Tools can be signed, but not directly notarized".
- klmr 6y agoYou need to have Xcode installed, but you don’t need to actually use the Xcode GUI for notarisation, you can use command line tools via `xcrun {altool,stapler}` to achieve the same. My company is distributing a Java application with a compiled JNI component written in C++, and I created the macOS distribution process for the app. It’s fully command-line based for automated deployment. Packaging and notarisation is a pain, but it is possible, even though the app we’re distributing is self-contained, so it includes a minimal JRE distribution, dynamic libraries, utility binaries, and a loader. All of these components must be code-signed and notarised (not individually, only the complete bundle is submitted, but all components are inspected).