From 077309cf003e4dbed33ffb8d00efcbfcd7d561c3 Mon Sep 17 00:00:00 2001 From: OmikronApex Date: Fri, 10 Jul 2026 14:04:45 +0200 Subject: [PATCH] fix(build): preserve mac entitlements through Velopack re-sign Same gap as nightly.yml: vpk pack --signAppIdentity without --signEntitlements strips electron-builder's entitlements (audio-input, allow-jit, ...) from the release feed's .app. Co-Authored-By: Claude Fable 5 --- .github/workflows/build.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index c4ed6b0..82e705a 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -432,6 +432,11 @@ jobs: # leaving --keychain off keeps both sides pointing at the same # store. (build.keychain only holds the signing cert, which # codesign finds via the keychain search list.) + # --signEntitlements is mandatory: vpk re-signs the bundle, and a + # codesign without an entitlements file STRIPS the ones + # electron-builder applied (audio-input, allow-jit, ...) — the + # hardened-runtime app then gets mic access auto-denied with no + # TCC prompt. xcrun notarytool store-credentials "velopack-notary" \ --apple-id "$APPLE_ID" \ --password "$APPLE_APP_SPECIFIC_PASSWORD" \ @@ -444,6 +449,7 @@ jobs: --mainExe "$mainexe" \ -o release/velopack \ --signAppIdentity "$APPLE_SIGNING_IDENTITY" \ + --signEntitlements resources/entitlements.mac.plist \ --notaryProfile "velopack-notary" fi