Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260916-1757-cvedb-developer-id-signed-notarized

rdmsm4x-changelog-20260916-1757-cvedb-developer-id-signed-notarized

Delivered Developer ID signed, notarized, and stapled universal2 release of cveDB application suite per DEC-20260909-03 and TASK-20260909-06.

Scope

What Changed & Why

  1. Pre-signing Test Verification:

    • Executed go test -v ./... covering all 24 Go packages (including adversarial, challenge, e2e, integration suites).
    • Verified 210 / 210 tests passed (100.0% pass rate) with zero failures.
  2. Universal2 Build Pipeline:

    • Authored canonical build.sh supporting --sign-notarize.
    • Built cveDB.app universal2 bundle via XcodeGen + xcodebuild (ARCHS="arm64 x86_64", ONLY_ACTIVE_ARCH=NO).
    • Built standalone Swift CLI cvedb-app via swift build -c release --product cvedb-app --arch arm64 --arch x86_64.
    • Built standalone Go CLI cvedb via cross-compilation (GOARCH=arm64 and GOARCH=amd64) and combined with lipo -create.
    • Verified universal2 x86_64 arm64 architectures with lipo -archs across all executables (cveDB.app/Contents/MacOS/cveDB, CVEDBCore.framework, dist/cvedb-gui, dist/cvedb-app, and dist/cvedb).
  3. Signing, Notarization & Stapling:

    • Signed embedded CVEDBCore.framework (inside-out signing) and standalone executables (dist/cvedb-gui, dist/cvedb-app, dist/cvedb) with Developer ID Application: east coast science, llc (ZU2882L4HT) (1C07FCD80C36EAD5D9E3B73F7ACCCA5368DC73FB), hardened runtime, and trusted timestamp.
    • Signed, submitted for notarization via ecs-notary profile, and stapled dist/cveDB.app via /Users/richh/dev/lib/app-baseline/scripts/ecs_sign_notarize.zsh.
    • Notarization submission d7a1eb84-fc14-46ab-b740-9ad5864b60e9 status: Accepted.
    • Gatekeeper verified spctl -a -vv -t exec -> source=Notarized Developer ID.
    • Stapler validated xcrun stapler validate -> The validate action worked!.
  4. Artifact Preservation & Release Evidence:

    • Preserved stapled cveDB.app, cveDB.zip, cvedb-gui, cvedb-app, cvedb, and RECEIPT.md under /Users/richh/dev/_handoff/cvedb-signed-20260916/.
    • Committed build.sh and docs/release-evidence/RECEIPT.md at commit 693da2acb09168559555004db6c8f84e7bba0e46 on main.
    • Pushed main to fleet (git.ecs0.net:git/apps/cvedb.git) and backup (github.com:richhdoty/rdmsm4x-dev-apps-cvedb.git).
    • Cleanly removed worktree /Users/richh/dev/_worktrees/cvedb-signed-task-20260909-06 after verifying handoff directory contents.

Exact Files Touched

Verification Evidence