Files
navi/docs/signing.md
T
M4andCursor 621c847cb3 Release 3.8.2.1: reliability, UI probe/logs, CI, signing gates.
Clear sysproxy on core death; probe+reconnect; subscription prune;
Best ignores soft UDP; Windows tray; Android protocol gate; CI workflows.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:44:48 +03:00

1.4 KiB

Code signing (release)

macOS

  1. Create a Developer ID Application certificate in Apple Developer.
  2. Store notary credentials once:
xcrun notarytool store-credentials "navis-notary" \
  --apple-id "you@example.com" \
  --team-id "TEAMID" \
  --password "app-specific-password"
  1. Build with identity (packmac picks it up):
export NAVIS_CODESIGN_IDENTITY="Developer ID Application: Example Ltd (TEAMID)"
./scripts/build-macos-arm64.sh
  1. Notarize the DMG:
export NAVIS_NOTARY_PROFILE="navis-notary"
./scripts/sign-macos.sh dist/navis-release/darwin-arm64/Navis.dmg

Without these env vars, packmac uses ad-hoc signing (-) — fine for local/dev.

For a release gate (fail if unsigned):

export REQUIRE_CODESIGN=1
export NAVIS_CODESIGN_IDENTITY="Developer ID Application: Example Ltd (TEAMID)"
./scripts/build-macos-arm64.sh

In-app macOS updates do not re-sign with ad-hoc - (that would strip Developer ID). They only re-sign when NAVIS_CODESIGN_IDENTITY is set to a real identity.

Windows

Sign Navis.exe with Authenticode (EV or standard code signing cert):

signtool sign /fd SHA256 /tr http://timestamp.digicert.com /td SHA256 /a dist\navis-release\Navis.exe
signtool verify /pa dist\navis-release\Navis.exe

Then refresh sha256 in dist/update.json (or re-run the Windows release script that stamps it).