#!/usr/bin/env bash # # Builds a distributable Snaggle.app and wraps it in a DMG. # # ./scripts/release.sh # ad-hoc signed (no Apple Developer account needed) # ./scripts/release.sh --developer-id # Developer ID + notarisation (paid account) # # The ad-hoc build runs anywhere, but macOS marks it as unverified: whoever downloads it has # to allow it once under System Settings > Privacy & Security. See README "Installing". # set -euo pipefail cd "$(dirname "$0")/.." MODE="adhoc" [[ "${1:-}" == "--developer-id" ]] && MODE="developer-id" # Xcode itself is required; the Command Line Tools package alone cannot build a project. if ! xcodebuild -version >/dev/null 2>&1; then echo "error: xcodebuild needs a full Xcode installation." >&2 echo "Active developer directory: $(xcode-select -p 2>/dev/null)" >&2 echo >&2 echo "Point it at Xcode and try again:" >&2 echo " sudo xcode-select -s /Applications/Xcode.app/Contents/Developer" >&2 exit 1 fi BUILD_DIR="build" DERIVED="$BUILD_DIR/DerivedData" EXPORT_DIR="$BUILD_DIR/export" DMG="$BUILD_DIR/Snaggle.dmg" NOTARY_PROFILE="${NOTARY_PROFILE:-SnaggleNotary}" rm -rf "$EXPORT_DIR" "$DMG" mkdir -p "$BUILD_DIR" if [[ "$MODE" == "adhoc" ]]; then echo "==> Building (ad-hoc signature)" xcodebuild \ -project Snaggle.xcodeproj \ -scheme Snaggle \ -configuration Release \ -destination 'platform=macOS,arch=arm64' \ -derivedDataPath "$DERIVED" \ CODE_SIGN_IDENTITY="-" \ CODE_SIGN_STYLE=Manual \ DEVELOPMENT_TEAM="" \ build mkdir -p "$EXPORT_DIR" cp -R "$DERIVED/Build/Products/Release/Snaggle.app" "$EXPORT_DIR/" APP="$EXPORT_DIR/Snaggle.app" # Apple silicon refuses to run a binary with no signature at all, so re-sign ad-hoc # to be certain every nested item is covered. echo "==> Ad-hoc signing" codesign --force --deep --sign - --options runtime "$APP" codesign --verify --verbose=2 "$APP" else ARCHIVE="$BUILD_DIR/Snaggle.xcarchive" rm -rf "$ARCHIVE" echo "==> Archiving" xcodebuild archive \ -project Snaggle.xcodeproj \ -scheme Snaggle \ -configuration Release \ -destination 'platform=macOS,arch=arm64' \ -archivePath "$ARCHIVE" echo "==> Exporting" xcodebuild -exportArchive \ -archivePath "$ARCHIVE" \ -exportOptionsPlist scripts/ExportOptions.plist \ -exportPath "$EXPORT_DIR" APP="$EXPORT_DIR/Snaggle.app" echo "==> Notarising (this can take a few minutes)" ZIP="$BUILD_DIR/Snaggle-notarize.zip" rm -f "$ZIP" ditto -c -k --keepParent "$APP" "$ZIP" xcrun notarytool submit "$ZIP" --keychain-profile "$NOTARY_PROFILE" --wait xcrun stapler staple "$APP" rm -f "$ZIP" fi echo "==> Building DMG" STAGING="$BUILD_DIR/dmg-staging" rm -rf "$STAGING" mkdir -p "$STAGING" cp -R "$APP" "$STAGING/" ln -s /Applications "$STAGING/Applications" cp docs/INSTALL.txt "$STAGING/" 2>/dev/null || true hdiutil create -volname "Snaggle" -srcfolder "$STAGING" -ov -format UDZO "$DMG" rm -rf "$STAGING" echo echo "App: $APP" echo "DMG: $DMG" if [[ "$MODE" == "adhoc" ]]; then echo echo "Ad-hoc signed. Tell people to open it once via" echo " System Settings > Privacy & Security > Open Anyway" echo "Control-click > Open no longer works on macOS 15 and later." fi