Now that native Windows and macOS builders exist, nothing needs cross-building.
Workflow
Three build jobs (linux, windows, macos) feed a single publish job. Publishing is separate so parallel builds cannot race to create the release and fail on a duplicate tag.
Windows gets its icon back
signAndEditExecutable: false was suppressing rcedit, which is what embeds the icon and version resources into the exe — the v1.0.0 exe shipped with the stock Electron icon because of it. Building natively means that flag can go. Adds an NSIS installer alongside the portable zip.
macOS
Adds a dmg target, which cannot be produced off macOS. Builds both arch slices on the M-series machine.
Before tagging
All three runners must be registered — ubuntu-latest, windows-latest, macos-arm64. A job with no matching runner queues silently rather than failing. A RELEASE_TOKEN secret is also required.
Builds remain unsigned, so Gatekeeper and SmartScreen warnings persist until certificates exist.
Now that native Windows and macOS builders exist, nothing needs cross-building.
## Workflow
Three build jobs (`linux`, `windows`, `macos`) feed a single `publish` job. Publishing is separate so parallel builds cannot race to create the release and fail on a duplicate tag.
## Windows gets its icon back
`signAndEditExecutable: false` was suppressing `rcedit`, which is what embeds the icon and version resources into the exe — the v1.0.0 exe shipped with the stock Electron icon because of it. Building natively means that flag can go. Adds an NSIS installer alongside the portable zip.
## macOS
Adds a `dmg` target, which cannot be produced off macOS. Builds both arch slices on the M-series machine.
## Before tagging
All three runners must be registered — `ubuntu-latest`, `windows-latest`, `macos-arm64`. A job with no matching runner **queues silently** rather than failing. A `RELEASE_TOKEN` secret is also required.
Builds remain unsigned, so Gatekeeper and SmartScreen warnings persist until certificates exist.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Splits the release workflow into linux, windows and macos jobs feeding a
single publish job. The publish step is separate so parallel builds cannot
race to create the release and fail on a duplicate tag.
Windows now builds natively, so signAndEditExecutable no longer has to be
disabled. That flag was suppressing rcedit, which is what embeds the icon
and version resources -- the v1.0.0 exe shipped with the stock Electron
icon as a result. Also adds an NSIS installer alongside the portable zip.
macOS gains a dmg target, which cannot be produced off macOS. Builds stay
unsigned pending a Developer ID, with CSC_IDENTITY_AUTO_DISCOVERY disabled
so electron-builder builds unsigned instead of failing on a real Mac.
Nothing cross-builds now; all three runners must be registered before
tagging, since a job with no matching runner queues silently.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
jknapp
merged commit f8d10d3a24 into main2026-08-29 01:53:40 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Now that native Windows and macOS builders exist, nothing needs cross-building.
Workflow
Three build jobs (
linux,windows,macos) feed a singlepublishjob. Publishing is separate so parallel builds cannot race to create the release and fail on a duplicate tag.Windows gets its icon back
signAndEditExecutable: falsewas suppressingrcedit, which is what embeds the icon and version resources into the exe — the v1.0.0 exe shipped with the stock Electron icon because of it. Building natively means that flag can go. Adds an NSIS installer alongside the portable zip.macOS
Adds a
dmgtarget, which cannot be produced off macOS. Builds both arch slices on the M-series machine.Before tagging
All three runners must be registered —
ubuntu-latest,windows-latest,macos-arm64. A job with no matching runner queues silently rather than failing. ARELEASE_TOKENsecret is also required.Builds remain unsigned, so Gatekeeper and SmartScreen warnings persist until certificates exist.
🤖 Generated with Claude Code