From bfdc6fde9d0e0d6ea68d7aa1e740cf1988294f9d Mon Sep 17 00:00:00 2001 From: Claude Fable 5 Date: Sat, 5 Sep 2026 10:03:40 +0400 Subject: [PATCH] release: spctl gate only hard-fails when the build was notarized Un-notarized fallback builds (Apple Development identity) are rejected by spctl by design; the script must still publish them with a warning, otherwise the fallback path can never release. Co-Authored-By: Claude Fable 5.1 --- scripts/publish-update.sh | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/scripts/publish-update.sh b/scripts/publish-update.sh index 6a636d5..fb8c231 100755 --- a/scripts/publish-update.sh +++ b/scripts/publish-update.sh @@ -359,8 +359,11 @@ SPCTL_STATUS=$? set -e echo "${SPCTL_OUTPUT}" if [[ "${SPCTL_STATUS}" -ne 0 ]] || ! grep -qi 'accepted' <<<"${SPCTL_OUTPUT}"; then - echo "spctl did not report accepted for ${APP_BUNDLE}." >&2 - exit 1 + if [[ "${NOTARIZED}" == "true" ]]; then + echo "spctl did not report accepted for ${APP_BUNDLE} although it was notarized." >&2 + exit 1 + fi + echo "WARNING: Gatekeeper does not accept this build (not notarized). First install on other Macs needs right-click > Open." >&2 fi TEAM_IDENTIFIER="$(codesign -dv "${APP_BUNDLE}" 2>&1 | awk -F= '/^TeamIdentifier=/{print $2}')"