npm ci
npm run licenses # no runtime dependency outside the allow-list
npm run typecheck
npm test # 256 tests, 63 checked against R
npm run build
npm run examples # regenerate the worked projects
npm run screenshots # regenerate the README and site pictures (needs npm run dev)If R is installed, also confirm the fixtures still match the oracle:
Rscript validation/generate/reference.R
git diff --exit-code validation/fixtures/ # must be emptyA non-empty diff means either a regression or that R itself has changed. Find out which before releasing. Never commit a hand-edited fixture.
The README and the landing page carry live badges from shields.io and the Actions badge. They need no maintenance now the repository is public.
Three files must agree, or the built app reports the wrong version:
package.json→versionsrc-tauri/tauri.conf.json→versionsrc-tauri/Cargo.toml→versionsrc/app/model.ts→APP_VERSION, which is what appears in methods sentences and saved projects
npm run desktop:dmg # macOS: app + DMG, verified to mount
npm run desktop:build:installers # Linux and WindowsmacOS is packaged by scripts/make-dmg.sh rather than Tauri's own DMG step.
Tauri's shells out to bundle_dmg.sh, which drives Finder over AppleScript and
fails with AppleEvent timed out (-1712) on any machine without a logged-in
desktop session, CI runners included.
Builds are unsigned. macOS Gatekeeper and Windows SmartScreen both warn on first launch, and unsigned scientific software gets abandoned at that dialog. This is the main thing standing between the current alpha and a 1.0 that labs can be asked to install.
Neither can be automated away: both require the project owner's legal identity
and payment. The workflow is already wired for both. Every signing step in
.github/workflows/release.yml is guarded on its own secret and skips itself
when that secret is unset, so unsigned builds keep working and nothing has to
change on the day a certificate arrives. The secrets below are the whole job.
| Secret | Used for |
|---|---|
APPLE_CERTIFICATE |
The Developer ID certificate, as base64 of the .p12 |
APPLE_CERTIFICATE_PASSWORD |
The password that .p12 was exported with |
APPLE_SIGNING_IDENTITY |
Developer ID Application: NAME (TEAMID) |
APPLE_ID, APPLE_APP_PASSWORD, APPLE_TEAM_ID |
Notarisation |
AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID |
Trusted Signing credentials |
AZURE_SIGNING_ENDPOINT, AZURE_SIGNING_ACCOUNT, AZURE_CERTIFICATE_PROFILE |
Which certificate profile to sign with |
Export the .p12 with:
base64 -i DeveloperID.p12 | pbcopy # paste as APPLE_CERTIFICATE- Enrol in the Apple Developer Program (~$99/year).
- Create a Developer ID Application certificate and install it in the login keychain.
- Create an app-specific password for notarisation.
- Set, in the release environment:
APPLE_SIGNING_IDENTITY="Developer ID Application: NAME (TEAMID)" APPLE_ID=... APPLE_PASSWORD=... # the app-specific password APPLE_TEAM_ID=... - Add to
src-tauri/tauri.conf.jsonunderbundle.macOS:"signingIdentity": "-", "hardenedRuntime": true
- Tauri signs and notarises during
tauri buildonce those are present. Verify withspctl -a -vvv -t install /path/to/AssayPlot.app, which should report accepted, source=Notarized Developer ID.
- Obtain an OV or EV code-signing certificate. Issuance takes weeks and, since 2023, requires hardware-backed key storage (a token or a cloud HSM).
- Since a hardware-backed key cannot be put in a repository secret, signing
goes through Azure Trusted Signing: set the six
AZURE_*secrets above and the release workflow signs the.exeand.msiafter the build. No change totauri.conf.jsonis needed.
An EV certificate builds SmartScreen reputation immediately; an OV one accrues it over time and downloads, so early users will still see the warning.
AppImage and .deb are unsigned by convention. Publish SHA-256 checksums beside
the artefacts.
git tag -a v0.7.0 -m "AssayPlot 0.5.0"
git push origin v0.7.0CI builds macOS, Linux and Windows and attaches the artefacts. Publish checksums with them.
State plainly:
- Anything that changes a number. If a statistical fix alters results, say which procedures and by how much, so anyone who has already published can check. This matters more than any feature.
- New analyses and plot types.
- Whether the build is signed.
- Any change to the project file format, and whether older projects still open.