Repository navigation
Sign Mac OS Installer packages #9139
Description
Activity
- addedenhancementa request to improve CLIa request to improve CLItech-debtA chore that addresses technical debtA chore that addresses technical debt
on May 29, 2024 - added a commit that references this issue
on May 29, 2024 As I was reading https://lokal.so/blog/guide-to-sign-and-notarize-your-go-app-for-outside-mac-app-store-distribution I noticed that they notarize the installer
.pkg. We currently notarize the contents, and hadn't considered notarizing the.pkgitself. Not sure what's necessary here but wanted to call it out.There's also some
staplingstep which I've never seen before.Reacted by Andy Feller, aapk64926, Osiloko12 and kobarm- addedcoreThis issue is not accepting PRs from outside contributorsThis issue is not accepting PRs from outside contributorsand removedneeds-triageneeds to be reviewedneeds to be reviewed
on Jun 24, 2024 As part of this work, the GitHub CLI website should be updated, directing users to download the Mac universal binary
47 remaining items
seems previous reply contained some hidden/stripped URL?
e-mail notification was writing:
bangtrabas left a comment (#9139).
[url]strange to see all this spam here
Reacted by Babak K. Shandizngocgiau030322-stack commented
on Feb 18, 2026 on Feb 18, 2026 · Hidden as spamshow commentMore actionsSome caveats:
- when the Developer ID certificate used to sign .pkg expires, those previously signed .pkg are not installable anymore.
- if one doesn't staple the notarization ticket then when there's no network available the pkg won't install (Gatekeeper can't fetch the ticket)
a summary by Copilot:
Summary: macOS PKG Signing & Notarization (Offline Behavior Included)
- Signing a PKG
- You must sign a .pkg with a Developer ID Installer certificate.
- Use productsign to apply the signature.
- This signature ensures integrity and allows the PKG to be notarized.
- Notarization
- After signing, you submit the PKG to Apple for notarization.
- Apple scans it and issues a notarization ticket.
- Notarization alone does not embed the ticket into the PKG.
- Stapling
- Stapling attaches the notarization ticket directly into the PKG:
xcrun stapler staple signed.pkg - A stapled PKG is self‑contained and can be validated entirely offline.
- What happens if you don’t staple?
- The PKG does not contain the notarization ticket.
- macOS must contact Apple’s servers to fetch the ticket at install time.
- Without internet, Gatekeeper cannot verify the notarization.
- Result: installation fails on offline machines.
- Final rule
If you want your PKG to install without internet access, stapling is mandatory.
- addedpitchpitched internally for prioritisationpitched internally for prioritisation
on Mar 10, 2026 - removedpitchpitched internally for prioritisationpitched internally for prioritisation
on May 21, 2026 Is this still being considered? Both this one and #13103 are kind of important.
Reacted by Mark Tomlin and Michael Ruhwedel
Describe the feature or problem you’d like to solve
Mac OS Installer package support added in #7554 should sign
.pkgwith an appropriate Developer ID Installer-signing identity.sign_macoslogic withinscript/signscript/pkgmacosAdditional context
The existing GitHub CLI deployment workflow only has access to Developer ID Application certificate, which cannot be reused in for Installer packages.