You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(release): the macOS signing keychain is stood up where its password is known
electron-builder makes its own keychain and unlocks it with a password it
generated. On the runner provisioner that landed 2026-08-28 that unlock fails —
`security set-key-partition-list` reports the passphrase as wrong, three
attempts, before anything is signed — while the same five secrets signed v0.61.0
fine forty minutes earlier on 20260707.563. Same image (macos-26-arm64), same
code path, different provisioner.
So the keychain is created here with a password this job chose, the .p12 is
imported into it, and electron-builder is handed it through CSC_KEYCHAIN. It
then signs out of a keychain that is already unlocked rather than making one.
A missing identity signs nothing and says nothing, which would read as a
successful unsigned release — so the step asks the keychain for a Developer ID
Application identity and fails if it has none.
CSC_LINK goes empty on BOTH legs now. It is electron-builder's platform-neutral
variable, and the Windows leg seeing a certificate is what shipped v0.36.0 with
an installer signed by an Apple identity that electron-updater then refused.
0 commit comments