Skip to content

macOS binaries not codesigned #5468

Description

@llvm-beanz

Describe the bug

gh 2.8.0 does not run on macOS without disabling system security settings because the binary is not code signed.

Steps to reproduce the behavior

  1. Download and extract gh 2.8.0 macOS binaries
  2. Run codesign -verify <path to gh>
  3. See error:
> codesign -verify ./gh_2.8.0_macOS_amd64/bin/gh
./gh_2.8.0_macOS_amd64/bin/gh: code object is not signed at all

Expected vs actual behavior

Binaries shipped in releases for macOS should be codesigned

Activity

  1. samcoe commented on Apr 15, 2022

    @samcoe
    Contributor

    @llvm-beanz Thanks for writing in, going to close as a duplicate of #2426 please direct all comments/questions/concerns to that issue please.

  2. llvm-beanz commented on Apr 15, 2022

    @llvm-beanz
    Author

    As I tried to comment in that issue. This is not an issue related to Apple Silicon. You're shipping insecure binaries that cannot be run on any mac without disabling OS security systems.

  3. mislav commented on May 4, 2022

    @mislav
    Contributor

    @llvm-beanz My colleague Sam closed this as a duplicate of another issue not because they are identical, but because we plan to sign our binaries to better support Apple silicon. As a result, all our binaries will get code-signed, no matter if you're downloading them on an M1 machine or not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingneeds-triageneeds to be reviewed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions