I am trying to write a script to notarize an app for distribution outside the Mac App Store. I have (in the past) successfully notarized a .dmg but for some reason I am running into trouble with a .zip file. The error I am receiving in the log file from notarization is that there is no code signature present.
So here is my notarization code:
cd app && zip MyZip.zip Test.app
cd -
xcrun altool --notarize-app \
--file "app/Myzip.zip" \
--username "abcabcabc" \
--password "abcabcabc" \
--asc-provider "abcabcabc" \
--primary-bundle-id "a.b.c.com"
When I check to verify the code signature on the Test.app, it appears to be fine:
codesign -vvv --deep --strict app/Test.app
app/Test.app: valid on disk
app/Test.app: satisfies its Designated Requirement
Running the same on the .zip file--as expected, returns an error:
codesign -vvv --deep --strict app/MyZip.zip
app/MyZip.zip: code object is not signed at all
Which is correct, as I did not sign the zip file. However, when I read other people's experiences, they seem to talk about uploading .zip files for notarization as if there is no problem (for example, steps 2 and 3 here: What is the most efficient way to notarize and staple a .zip containing a .app?). Has something changed since 2019--do I now need to manually use the codesign tool to sign my zip file using the same identity that the app is signed with? I even tried the following, as requested by Apple in the documentation (https://developer.apple.com/documentation/security/notarizing_macos_software_before_distribution/customizing_the_notarization_workflow):
/usr/bin/ditto -c -k --keepParent "app/Test.app" "app/MyZip.zip"
but running codesign -vvv --deep --strict app/MyZip.zip still returns code object is not signed at all.
Do I need to custom code sign? Or is there a way to zip it but somehow preserve the codesign signature? Thank you.