Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
107 changes: 107 additions & 0 deletions .github/workflows/desktop-notarized.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
# Copyright 2026 Firefly Software Foundation.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# Author: Firefly Software Foundation
# SPDX-License-Identifier: Apache-2.0

name: Notarized macOS installers

on:
workflow_dispatch:
inputs:
notarize:
description: 'Sign and submit this exact release tag to Apple (requires protected environment approval)'
type: boolean
required: true
default: false

permissions:
contents: read

jobs:
macos:
if: >-
github.event_name == 'workflow_dispatch' && inputs.notarize == true &&
github.repository == 'fireflyframework/firefly-weave' && startsWith(github.ref, 'refs/tags/v')
environment: macos-release-signing
strategy:
fail-fast: false
matrix:
include:
- os: macos-15
target: aarch64-apple-darwin
- os: macos-15-intel
target: x86_64-apple-darwin
runs-on: ${{ matrix.os }}
timeout-minutes: 120
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.sha }}
fetch-depth: 0
persist-credentials: false
- uses: astral-sh/setup-uv@v6
with:
version: '0.11.19'
python-version: '3.12.13'
- name: Verify exact release source without credentials
run: uv run --no-project python desktop/scripts/notarize_macos.py --verify-source
- uses: actions/setup-node@v4
with:
node-version: '24.15.0'
cache: npm
cache-dependency-path: |
studio/package-lock.json
desktop/package-lock.json
- uses: dtolnay/rust-toolchain@1.96.0
with:
components: rustfmt,clippy
targets: ${{ matrix.target }}
- name: Prepare locked tools
run: |
uv sync --locked --extra studio
uv pip install pyinstaller==6.16.0
npm ci --prefix studio
npm ci --prefix desktop
- name: Verify source and compile Studio before loading credentials
run: |
uv run --no-sync python -m pytest tests/unit/test_macos_seal.py tests/unit/test_macos_notarization.py -q
npm run check --prefix studio
npm test --prefix studio
npm run build --prefix studio
cargo fmt --check --manifest-path desktop/src-tauri/Cargo.toml
cargo clippy --locked --manifest-path desktop/src-tauri/Cargo.toml -- -D warnings
cargo test --locked --manifest-path desktop/src-tauri/Cargo.toml
- name: Sign, notarize, verify and collect exact installers
env:
APPLE_CERTIFICATE: ${{ secrets.APPLE_CERTIFICATE }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_API_ISSUER: ${{ secrets.APPLE_API_ISSUER }}
APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }}
APPLE_API_PRIVATE_KEY: ${{ secrets.APPLE_API_PRIVATE_KEY }}
run: uv run --no-sync python desktop/scripts/notarize_macos.py --target ${{ matrix.target }}
- name: Remove temporary signing credentials even after interruption
if: always()
run: uv run --no-project python desktop/scripts/notarize_macos.py --cleanup
- name: Retain verified notarized installers only
uses: actions/upload-artifact@v4
with:
name: weave-studio-${{ github.ref_name }}-${{ matrix.target }}-notarized
if-no-files-found: error
path: desktop/work/notarized-assets/**
# This opt-in workflow retains artifacts; it never creates or modifies a release.
10 changes: 10 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,16 @@ SPDX-License-Identifier: Apache-2.0

# Changelog

## 0.1.0a14

- Add a detached Docker development platform through `weave platform up`,
reusing owned databases, identity setup, workspace creation, and user roles.
Keep the foreground API mode available for existing installations.
- Prepare an explicit Developer ID signing and notarization path for macOS
releases. Apple credentials are required; ordinary builds remain ad-hoc signed.
- Pin the Agentic and Files 0.1.6 packages to core 0.1.0a14 without changing their
execution behavior or the database schema.

## 0.1.0a13

- Retry explicit platform capacity rejections while a worker reads its task
Expand Down
44 changes: 22 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ maps service tasks, user tasks, gateways, and timers to Weave steps.

## What you get

The **v0.1.0a13 alpha** release provides the **API, CLI, Python SDK, and Studio**
The **v0.1.0a14 alpha** release provides the **API, CLI, Python SDK, and Studio**
visual workspace, with human-task inboxes, email conversations, execution
management, and administration of people and access. Run Weave as a standalone
service or embed it in another product.
Expand Down Expand Up @@ -81,7 +81,7 @@ See the illustrated [AI workflow guide](docs/guides/ai-workers.md) and
Read the [capability matrix](docs/capabilities.md) for tested boundaries and
live-provider checks that remain environment-specific.

Studio runs in your browser from the [installed CLI](docs/guides/studio.md#install-the-alpha13-browser-application)
Studio runs in your browser from the [installed CLI](docs/guides/studio.md#install-the-alpha14-browser-application)
or as a [desktop app](docs/guides/desktop.md). The macOS desktop bundles
are ad-hoc signed, not Developer ID signed or notarized, so macOS may ask you to
approve them; do not use the alpha5 macOS installers, which were damaged. The
Expand Down Expand Up @@ -119,20 +119,20 @@ integration code. Each has its own guide, so you can stop at the result you need
## Install and discover the CLI

On macOS, Linux, or WSL, install **Python 3.12 or newer** with `venv` support,
then run this block in Bash or Zsh. It installs the pinned **v0.1.0a13 alpha**
then run this block in Bash or Zsh. It installs the pinned **v0.1.0a14 alpha**
into your user account without `sudo`, Git, or Docker:

```sh
(
# Stop if downloading the installer fails.
set -o pipefail
curl --proto '=https' --tlsv1.2 -fsSL \
https://github.com/fireflyframework/firefly-weave/releases/download/v0.1.0a13/install.sh \
| sh -s -- --version v0.1.0a13
https://github.com/fireflyframework/firefly-weave/releases/download/v0.1.0a14/install.sh \
| sh -s -- --version v0.1.0a14
)
```

Expected: `Installed Firefly Weave 0.1.0a13:` followed by the command's path. Then
Expected: `Installed Firefly Weave 0.1.0a14:` followed by the command's path. Then
make the default command directory available in this terminal and look around:

```sh
Expand All @@ -146,7 +146,7 @@ weave help workflow
weave docs platform
```

Expected: `Firefly Weave 0.1.0a13`, the command overview, the `workflow`
Expected: `Firefly Weave 0.1.0a14`, the command overview, the `workflow`
commands, and the address of the platform guide. You do not need to learn every
command first: help explains each family and its next steps. The
[installation guide](docs/installation.md) covers choosing Python, a permanent
Expand Down Expand Up @@ -179,27 +179,27 @@ Compose files and setup helpers. Clone the tag that matches the CLI:

```sh
# Keep the platform files at the same version as the CLI.
git clone --branch v0.1.0a13 --single-branch https://github.com/fireflyframework/firefly-weave.git
git clone --branch v0.1.0a14 --single-branch https://github.com/fireflyframework/firefly-weave.git
cd firefly-weave

# Check prerequisites, then prepare private settings and dependencies once.
# Check prerequisites, then start a persistent Docker platform and a sign-in account.
weave platform doctor
weave platform setup
weave platform up --username developer

# Keep this terminal open while the API runs.
weave platform start
# Confirm readiness and copy the printed sign-in command.
weave platform status
```

Expected: `doctor` reports your CLI version, the checkout, and the Docker
context; `setup` finishes without errors; and `start` keeps printing API logs.
In a second terminal at that checkout, run `weave platform status`, then
`weave platform demo` to save a first real run, and open the printed `/docs`
address to explore the API.
Expected: the API and Keycloak are ready, the example workflow succeeded, and
`up` prints a generated password once. Docker keeps the API running after you
close the terminal. Follow the printed `weave auth setup` command, sign in with
your new account, then run `weave studio`.

To sign in as a person, open Studio against it, and run REST calls, follow
steps 5 to 8 of [the local platform guide](docs/guides/local-platform.md). For a
shared installation, start with
[the deployment map](docs/operations/remote-deployment.md).
The [Docker development guide](docs/guides/docker-development.md) explains each
step, the architecture, stopping and resuming, and administrator roles. Existing
foreground installations continue to use `weave platform start`; see the
[individual setup steps](docs/guides/local-platform.md). For a shared
installation, start with [the deployment map](docs/operations/remote-deployment.md).

## Continue when you need more

Expand Down Expand Up @@ -265,7 +265,7 @@ path, and the detailed diagrams.

## Current release and limits

The recommended installation is **v0.1.0a13**, an **alpha** release. Download
The recommended installation is **v0.1.0a14**, an **alpha** release. Download
packages and checksums from
[GitHub Releases](https://github.com/fireflyframework/firefly-weave/releases).
The documentation on a branch describes the source on that branch; a release tag
Expand Down
8 changes: 4 additions & 4 deletions desktop/RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,16 +17,16 @@ SPDX-License-Identifier: Apache-2.0
-->
# Desktop release versions

The alpha13 product version is `0.1.0-alpha.13` in npm, Cargo and Tauri. It corresponds
to Python `0.1.0a13` and the repository prerelease tag `v0.1.0a13`.
The alpha14 product version is `0.1.0-alpha.14` in npm, Cargo and Tauri. It corresponds
to Python `0.1.0a14` and the repository prerelease tag `v0.1.0a14`.

Windows MSI uses the explicit numeric version `0.1.13`. Tauri's pinned bundler rejects
Windows MSI uses the explicit numeric version `0.1.14`. Tauri's pinned bundler rejects
nonnumeric prerelease identifiers when deriving MSI versions; its `windows.wix.version`
override supplies the valid numeric installer version while filenames retain the product
version. MSI compares only the first three fields. Future desktop alpha and stable
releases must advance this numeric installer counter: the stable product `0.1.0`
must not reset the MSI counter to `0.1.0`. The macOS internal bundle version also uses
numeric `0.1.13`; its displayed product version remains the alpha product version.
numeric `0.1.14`; its displayed product version remains the alpha product version.

The Desktop installers workflow builds on four native runners and is dispatchable by
an exact branch/tag ref. Versioned, target-specific unsigned artifacts contain only
Expand Down
4 changes: 2 additions & 2 deletions desktop/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion desktop/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@firefly-weave/desktop",
"version": "0.1.0-alpha.13",
"version": "0.1.0-alpha.14",
"private": true,
"license": "Apache-2.0",
"scripts": {
Expand Down
13 changes: 12 additions & 1 deletion desktop/scripts/build_sidecar.py
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,17 @@
from pathlib import Path


def signing_arguments(identity: str | None, root: Path) -> list[str]:
if not identity:
return []
return [
"--codesign-identity",
identity,
"--osx-entitlements-file",
str(root / "desktop/src-tauri/entitlements.plist"),
]


def main() -> None:
parser = argparse.ArgumentParser()
parser.add_argument("--target")
Expand Down Expand Up @@ -74,7 +85,7 @@ def main() -> None:
]
identity = os.environ.get("APPLE_SIGNING_IDENTITY")
if sys.platform == "darwin" and identity:
command[3:3] = ["--codesign-identity", identity]
command[3:3] = signing_arguments(identity, root)
subprocess.run(command, check=True, cwd=root)
extension = ".exe" if sys.platform == "win32" else ""
source = work / "dist" / ("weave-studio-host" + extension)
Expand Down
Loading
Loading