Build release artifacts¶
Follow the sections below, depending on the OS you want to build artifacts for. Linux artifacts can be built on macOS, via the use of containers.
Automated instructions help build things quicker. For an explanation of what they do under the hood, read Build release artifacts with Doit.
macOS¶
Automated¶
From your macOS terminal app:
-
export APPLE_ID=<email>in your terminal session - Build artifacts for Intel macOS with
make build-macos-intel - Build artifacts for Apple Silicon macOS with
make build-macos-arm
Manual steps¶
-
Checkout the dependencies, and clean your local copy:
-
Retrieve the container image and download the necessary assets:
-
Build the app bundle
-
Sign the application bundle, and notarize it
This command needs to run from an account with access to the code-signing certificate.
This command assumes the Apple Developer ID application password is stored in the Keychain and used specifically for
notarytool.# Sign the .App and make it a .dmg poetry run ./install/macos/build-app.py --only-codesign # Notarize it. This command must run from the MacOS UI, # inside a terminal application. xcrun notarytool submit ./dist/Dangerzone.dmg --apple-id $APPLE_ID --keychain-profile "dz-notarytool-release-key" --wait && xcrun stapler staple dist/Dangerzone.dmg # Copy the .dmg to the assets folder ARCH=$(uname -m) if [ "$ARCH" = "x86_64" ]; then ARCH="i686" fi cp dist/Dangerzone.dmg ~dz/release-assets/$VERSION/Dangerzone-$VERSION-$ARCH.dmg
Windows¶
-
Checkout the dependencies, and clean the local copy:
-
Download the container image with signatures:
-
Download the necessary assets with
poetry run mazette install - Run
poetry run .\install\windows\build-app.bat. After completion, the installer will be available atdist\Dangerzone.msi - Rename
Dangerzone.msitoDangerzone-$VERSION.msi.
Linux¶
Automated¶
- Run
make build-linux(not necessary if you've previously built artifacts for macOS)
Manual steps¶
Below we explain how we build packages for each Linux distribution we support.
Debian/Ubuntu¶
Because the Debian packages do not contain compiled Python code for a specific Python version, a single Debian package can be used for all of our Debian-based distros.
Create a Debian Bookworm development environment. Follow the instructions in the build section, or create it locally with:
# Create and run debian bookworm development environment
./dev_scripts/env.py --distro debian --version bookworm build-dev
./dev_scripts/env.py --distro debian --version bookworm run --dev bash
# Get the vendorized assets
poetry run mazette install
# Retrieve the latest container
poetry run dangerzone-image prepare-archive \
--image ghcr.io/freedomofpress/dangerzone/v1@sha256:${DIGEST} \
--output share/container.tar
# Create both .deb packages (dangerzone slim + dangerzone-full)
./dev_scripts/env.py --distro debian --version bookworm run --dev bash -c "cd dangerzone && ./install/linux/build-deb.py"
A single build-deb.py invocation produces both dangerzone_<version>_amd64.deb (slim, no bundled container.tar) and dangerzone-full_<version>_amd64.deb (with the container image bundled) under ./deb_dist.
Publish both .deb files under ./deb_dist to the freedomofpress/packages repo, by sending a PR. Follow the instructions in that repo on how to do so.
Fedora¶
Note
This procedure will have to be done for every supported Fedora version. In this section, Fedora 42 is used as an example.
Create a Fedora development environment. Follow the instructions in the build section, or create it locally with:
./dev_scripts/env.py --distro fedora --version 42 build-dev
./dev_scripts/env.py --distro fedora --version 42 run --dev bash
# Get the vendorized assets
poetry run mazette install
# Retrieve the latest container
poetry run dangerzone-image prepare-archive \
--image ghcr.io/freedomofpress/dangerzone/v1@sha256:${DIGEST} \
--output share/container.tar
# Create the dangerzone .rpm (without container):
./dev_scripts/env.py --distro fedora --version 42 run --dev bash -c "cd dangerzone && ./install/linux/build-rpm.py"
# Create the dangerzone-full .rpm (with container bundled):
./dev_scripts/env.py --distro fedora --version 42 run --dev bash -c "cd dangerzone && ./install/linux/build-rpm.py --full"
Publish both dangerzone-<version>.fc<NN>.x86_64.rpm (slim) and dangerzone-full-<version>.fc<NN>.x86_64.rpm (bundled container) under ./dist to the freedomofpress/packages repo, by sending a PR. Follow the instructions in that repo on how to do so.
Qubes¶
Create a .rpm for Qubes:
./dev_scripts/env.py --distro fedora --version 42 run --dev bash -c "cd dangerzone && ./install/linux/build-rpm.py --qubes"
and similarly publish it to the freedomofpress/packages repo.