krz/octosentry

macOS menu bar app to monitor GitHub security alerts github macos menubar security

Commit 739e452413

739e4524135af7301b485c924ea647917052d94d

parent: 22a7640f46

Unsigned

cmc <hello@cleberg.net> · 2026-07-18 05:25 UTC

Drop App Store from distribution docs

Not pursuing App Store submission — DMG + Homebrew only. Removed the
submission walkthrough and reframed the doc around the single channel;
also updated the Homebrew section since the tap is actually published
now, not just a template.

Layout: unified · split

DISTRIBUTION.md +24 −28
@@ -1,26 +1,9 @@
1# Distribution 1# Distribution
2 2
3octosentry ships on two channels with a single codebase and identical 3octosentry ships as a notarized DMG and via Homebrew — no App Store
4entitlements (spec §9) — the only divergence is signing method at export 4distribution. Same entitlements either way; there's only one channel.
5time and whether the update checker runs.
6 5
7## App Store 6## DMG
8
91. Requires an active Apple Developer Program membership and an **Apple
10 Distribution** certificate (Xcode > Settings > Accounts > Manage
11 Certificates).
122. Create the app record in [App Store Connect](https://appstoreconnect.apple.com)
13 with bundle ID `net.cleberg.octosentry`.
143. Archive: Product > Archive in Xcode (Release configuration).
154. In the Organizer, Distribute App > App Store Connect > Upload.
165. Complete the app listing (screenshots, description, privacy nutrition
17 label — [PrivacyInfo.xcprivacy](octosentry/PrivacyInfo.xcprivacy) already
18 declares no tracking and no collected data) and submit for review.
19
20The update checker (`UpdateStore`) detects the App Store receipt at
21runtime and never runs on this build — no code changes needed per release.
22
23## DMG (direct distribution)
24 7
25Requires a **Developer ID Application** certificate and notarization 8Requires a **Developer ID Application** certificate and notarization
26credentials stored once locally: 9credentials stored once locally:
@@ -43,18 +26,31 @@ scripts/build-dmg.sh 1.0.0
43 26
44This archives, exports with Developer ID signing, notarizes, staples the 27This archives, exports with Developer ID signing, notarizes, staples the
45ticket, and produces `build/octosentry-1.0.0.dmg`. Attach that file to 28ticket, and produces `build/octosentry-1.0.0.dmg`. Attach that file to
46the corresponding GitHub Release (`gh release create 1.0.0 build/octosentry-1.0.0.dmg`) 29the corresponding GitHub Release:
47— the update checker links there. 30
31```bash
32gh release upload 1.0.0 build/octosentry-1.0.0.dmg
33```
34
35The update checker (`UpdateStore`) links there.
48 36
49## Homebrew 37## Homebrew
50 38
51Not published yet. [Casks/octosentry.rb](Casks/octosentry.rb) is a 39Published at [zerolabsco/homebrew-tap](https://github.com/zerolabsco/homebrew-tap).
52template — to actually publish it: 40Users install via:
41
42```bash
43brew tap zerolabsco/tap
44brew install --cask octosentry
45```
46
47Per release, after uploading the new DMG to its GitHub Release:
53 48
541. Create a `zerolabsco/homebrew-tap` repo. 491. `shasum -a 256 build/octosentry-<version>.dmg`
552. Copy the cask there, filling in the real `sha256` of the released DMG 502. Update `version` and `sha256` in [Casks/octosentry.rb](Casks/octosentry.rb)
56 (`shasum -a 256 octosentry-1.0.0.dmg`). 51 (kept here for reference — the canonical copy lives in the tap repo).
573. Users install via `brew tap zerolabsco/tap && brew install --cask octosentry`. 523. Copy the updated file into a local clone of `zerolabsco/homebrew-tap`,
53 commit, and push.
58 54
59## Version bumps 55## Version bumps
60 56