Skip to content

Commit 5409af3

Browse files
committed
docs: document macOS Gatekeeper workaround for unsigned binaries
Pre-built release binaries aren't Apple-notarized, so macOS quarantines a downloaded copy and reports it as malware. Document the one-line `xattr -d com.apple.quarantine` fix (and the go install alternative) in the README and in every auto-generated release's notes.
1 parent 398badb commit 5409af3

2 files changed

Lines changed: 33 additions & 1 deletion

File tree

‎.github/workflows/release.yml‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,3 +30,22 @@ jobs:
3030
with:
3131
files: dist/*
3232
generate_release_notes: true
33+
body: |
34+
## Install
35+
36+
**Recommended (no warnings):**
37+
```bash
38+
go install github.com/ashishxcode/commit-chronicle/cmd/commit-chronicle@latest
39+
```
40+
41+
**Pre-built binary:** download for your OS/arch below, then:
42+
```bash
43+
chmod +x commit-chronicle-*
44+
# macOS only — clear the Gatekeeper quarantine flag:
45+
xattr -d com.apple.quarantine commit-chronicle-* 2>/dev/null || true
46+
mv commit-chronicle-* /usr/local/bin/commit-chronicle
47+
```
48+
49+
> macOS can't verify these binaries (they aren't Apple-notarized), so a
50+
> downloaded copy is quarantined and reported as "malware" / "cannot be
51+
> opened" until you run the `xattr` command above (or right-click → Open).

‎README.md‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,11 @@ For a window you choose, it gathers **everything you did**:
2525

2626
## Install
2727

28+
> **macOS users:** prefer Option 1 or 2 — building locally is never blocked by
29+
> Gatekeeper. The pre-built release binaries (Option 3) are not Apple-notarized,
30+
> so macOS will quarantine a downloaded copy and warn it "cannot be opened" /
31+
> "is malware"; clearing that takes one command (shown below).
32+
2833
### Option 1 — `go install` (needs Go 1.25+)
2934

3035
```bash
@@ -54,10 +59,18 @@ Grab the binary for your OS/arch from the
5459
[Releases](https://github.com/ashishxcode/commit-chronicle/releases) page, then:
5560

5661
```bash
57-
chmod +x commit-chronicle-* # macOS/Linux
62+
chmod +x commit-chronicle-* # macOS/Linux
63+
xattr -d com.apple.quarantine commit-chronicle-* 2>/dev/null || true # macOS only
5864
mv commit-chronicle-* /usr/local/bin/commit-chronicle
5965
```
6066

67+
The `xattr` line clears the Gatekeeper quarantine flag macOS adds to anything
68+
downloaded from the internet — without it you'll get a "cannot be opened
69+
because Apple cannot check it for malicious software" / malware warning, because
70+
the binaries aren't notarized. (You can also right-click the binary in Finder →
71+
**Open** the first time.) If you'd rather avoid this entirely, install with
72+
`go install` (Option 1), which compiles on your machine and is never quarantined.
73+
6174
Maintainers can produce all platform binaries with `make release` (output in
6275
`dist/`).
6376

0 commit comments

Comments
 (0)