# Code signing (release) ## macOS 1. Create a **Developer ID Application** certificate in Apple Developer. 2. Store notary credentials once: ```bash xcrun notarytool store-credentials "navis-notary" \ --apple-id "you@example.com" \ --team-id "TEAMID" \ --password "app-specific-password" ``` 3. Build with identity (packmac picks it up): ```bash export NAVIS_CODESIGN_IDENTITY="Developer ID Application: Example Ltd (TEAMID)" ./scripts/build-macos-arm64.sh ``` 4. Notarize the DMG: ```bash export NAVIS_NOTARY_PROFILE="navis-notary" ./scripts/sign-macos.sh dist/navis-release/darwin-arm64/Navis.dmg ``` Without these env vars, packmac uses **ad-hoc** signing (`-`) — fine for local/dev. ## Windows Sign `Navis.exe` with Authenticode (EV or standard code signing cert): ```bat signtool sign /fd SHA256 /tr http://timestamp.digicert.com /td SHA256 /a dist\navis-release\Navis.exe signtool verify /pa dist\navis-release\Navis.exe ``` Then refresh `sha256` in `dist/update.json` (or re-run the Windows release script that stamps it).