Skip to content

Sign Mac OS Installer packages #9139

Description

@andyfeller

Describe the feature or problem you’d like to solve

Mac OS Installer package support added in #7554 should sign .pkg with an appropriate Developer ID Installer-signing identity.

Additional context

The existing GitHub CLI deployment workflow only has access to Developer ID Application certificate, which cannot be reused in for Installer packages.

Activity

  1. JouniJouni93 commented on Jun 1, 2024

    @JouniJouni93
  2. williammartin commented on Jun 24, 2024

    @williammartin
    Member

    As I was reading https://lokal.so/blog/guide-to-sign-and-notarize-your-go-app-for-outside-mac-app-store-distribution I noticed that they notarize the installer .pkg. We currently notarize the contents, and hadn't considered notarizing the .pkg itself. Not sure what's necessary here but wanted to call it out.

    There's also some stapling step which I've never seen before.

  3. added
    coreThis issue is not accepting PRs from outside contributors
    and removed on Jun 24, 2024
  4. Infinnet commented on Jul 12, 2024

    @Infinnet
  5. sherwyn29 commented on Jul 15, 2024

    @sherwyn29
  6. sherwyn29 commented on Jul 15, 2024

    @sherwyn29
  7. KikeE36 commented on Aug 8, 2024

    @KikeE36
  8. KikeE36 commented on Aug 8, 2024

    @KikeE36
  9. andyfeller commented on Aug 12, 2024

    @andyfeller
    ContributorAuthor

    As part of this work, the GitHub CLI website should be updated, directing users to download the Mac universal binary

  10. 47 remaining items

  11. aliGabre commented on Jul 23, 2025

    @aliGabre
  12. bangtrabas commented on Jul 31, 2025

    @bangtrabas
  13. birbilis commented on Aug 1, 2025

    @birbilis

    seems previous reply contained some hidden/stripped URL?

    e-mail notification was writing:

    bangtrabas left a comment (#9139).
    [url]

    strange to see all this spam here

  14. GAB239419 commented on Dec 18, 2025

    @GAB239419
  15. ngocgiau030322-stack commented on Feb 18, 2026

    @ngocgiau030322-stack
  16. birbilis commented on Feb 18, 2026

    @birbilis

    Some caveats:

    1. when the Developer ID certificate used to sign .pkg expires, those previously signed .pkg are not installable anymore.
    2. if one doesn't staple the notarization ticket then when there's no network available the pkg won't install (Gatekeeper can't fetch the ticket)

    a summary by Copilot:

    Summary: macOS PKG Signing & Notarization (Offline Behavior Included)

    1. Signing a PKG
    • You must sign a .pkg with a Developer ID Installer certificate.
    • Use productsign to apply the signature.
    • This signature ensures integrity and allows the PKG to be notarized.
    1. Notarization
    • After signing, you submit the PKG to Apple for notarization.
    • Apple scans it and issues a notarization ticket.
    • Notarization alone does not embed the ticket into the PKG.
    1. Stapling
    • Stapling attaches the notarization ticket directly into the PKG:
      xcrun stapler staple signed.pkg
    • A stapled PKG is self‑contained and can be validated entirely offline.
    1. What happens if you don’t staple?
    • The PKG does not contain the notarization ticket.
    • macOS must contact Apple’s servers to fetch the ticket at install time.
    • Without internet, Gatekeeper cannot verify the notarization.
    • Result: installation fails on offline machines.
    1. Final rule
      If you want your PKG to install without internet access, stapling is mandatory.
  17. removed
    pitchpitched internally for prioritisation
    on May 21, 2026
  18. securitrees commented on Aug 8, 2026

    @securitrees

    Is this still being considered? Both this one and #13103 are kind of important.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    coreThis issue is not accepting PRs from outside contributorsenhancementa request to improve CLIpackagingtech-debtA chore that addresses technical debt

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions