Add code signing, notarization, and DMG packaging scripts

Enables distributing Galaxy.app to end users without Gatekeeper warnings.
Uses Samsung Developer ID Application certificate with hardened runtime.

Pipeline: cargo bundle → sign.sh → notarize.sh → package.sh → Galaxy.dmg

Entitlements:
- network.client (AWS Bedrock API calls)
- automation.apple-events (osascript for CLI install)
- cs.allow-unsigned-executable-memory (Metal shader compilation)

Orchestration scripts:
- build-debug.sh: full pipeline with debug build
- build-release.sh: full pipeline with release build

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
George Brancovici
2026-05-13 12:47:57 -04:00
co-authored by Claude Opus 4.6
parent cee61e2af0
commit c9492c90ea
6 changed files with 215 additions and 0 deletions
Executable
+14
View File
@@ -0,0 +1,14 @@
#!/bin/bash
set -e
cd "$(dirname "$0")"
echo "=== Galaxy Debug Build + Sign + Notarize + Package ==="
echo ""
cargo bundle --bin galaxy-oss --package galaxy
./sign.sh
./notarize.sh
./package.sh
echo ""
echo "=== Done. Distributable DMG: target/debug/bundle/osx/Galaxy.dmg ==="