Skip to content

Prepare build environments

macOS

Initial setup

  • Ensure that the build machine has:
    • Apple-trusted Developer ID Application: Freedom of the Press Foundation (94ZZGGGJ3W) code-signing certificates installed
  • Apple account must have:
    • A valid application password for notarytool in the Keychain. You can verify this by running:

      xcrun notarytool history --apple-id "<email>" --keychain-profile "dz-notarytool-release-key"
      

      If the key isn't found, add it to the Keychain by running:

      xcrun notarytool store-credentials dz-notarytool-release-key --apple-id <email> --team-id 94ZZGGGJ3W
      

      with the respective email. The team ID is retrieved from https://developer.apple.com -> Account -> Membership details -> Team ID.

On each release

  • Agree to any new terms and conditions in https://developer.apple.com, once you log in with FPF's Apple ID.
  • Upgrade "Command Line Tools" from "System Settings -> Software Update", from an account with admin privileges.
  • Upgrade Xcode from the App Store, from an account with admin privileges.
  • Update Docker Desktop and Podman Desktop to the latest versions.
  • Update Python to the latest supported version, following our instructions

Windows

The Windows release is performed in a Windows 11 virtual machine (as opposed to a physical one).

Initial Setup

On each release

  • Update WiX, if necessary
  • Update Python to the latest supported version, following our instructions