Assinatura de Código e Notarização
Entenda a importância da assinatura de código para Windows e da notarização para macOS, garantindo a confiança dos usuários e a conformidade com os requisitos de segurança.
Assinatura de Código e Notarização é uma aula grátis de Electron Desktop App Development no CoddyKit. Esta é a aula 2 de 4. Você pode ler a aula completa abaixo gratuitamente — depois pratica ao vivo no navegador com um editor de código integrado e um tutor de IA 24/7. Faz parte do caminho de aprendizado de Electron Desktop App Development, e seu progresso é sincronizado entre a web e o app CoddyKit. O curso de Electron Desktop App Development inclui 4 aulas no total.
Partes desta aula ainda não foram traduzidas e aparecem em inglês.
Building Trust with Code Signing
When you distribute your Electron app, users need to trust it. Operating systems like Windows and macOS have built-in security features to protect users from malicious software.
Code signing and notarization are essential steps to prove your app's authenticity and integrity, ensuring users feel safe installing it.
What is Code Signing?
Code signing is like attaching a digital signature to your application. It uses a cryptographic certificate issued by a trusted Certificate Authority (CA).
- Authenticity: Verifies the app comes from you, the publisher.
- Integrity: Confirms the app hasn't been tampered with since you signed it.
If the signature is invalid or altered, the OS will warn the user.
Trust on Windows
On Windows, unsigned applications often trigger security warnings like "Windows protected your PC" (SmartScreen filter).
A valid code signature helps your app pass these checks, giving users confidence and reducing installation friction. It also allows your app to be installed without extra administrator prompts for some operations.
Signing Windows Executables
To sign your Windows Electron app, you'll need a Code Signing Certificate. This is typically a PFX file containing your private key and certificate chain.
Tools like electron-builder simplify this process by letting you specify your certificate details in the configuration.
{
"build": {
"win": {
"target": "nsis",
"signingHashAlgorithms": ["sha256"],
"signAndEditExecutable": true
},
"cscKeyPassword": "your-cert-password",
"cscInstallerPassword": "your-cert-password",
"cscLink": "path/to/your/certificate.pfx"
}
}Time-Stamping Your Signature
When code signing, it's crucial to also time-stamp your signature. This ensures that even if your signing certificate expires, the signature remains valid because it was signed when the certificate was active.
Most signing tools, including electron-builder, can automatically add a time-stamp server URL to your signing process.
macOS Notarization Explained
For macOS, Apple introduced Notarization as an additional security check. It's an automated service that scans your app for malicious content and code signature issues.
Think of it as Apple giving your app a "seal of approval" before it can run smoothly on macOS Catalina and later.
Meeting Apple's Gatekeeper
macOS's security feature, Gatekeeper, blocks unsigned or unnotarized apps from running by default. Users will see a warning that the app "cannot be opened because the developer cannot be verified."
Notarization allows your app to pass Gatekeeper checks without annoying users or requiring them to bypass security settings manually.
Getting Ready for Notarization
To notarize your Electron app, you need:
- An Apple Developer ID.
- An app-specific password for your Apple ID.
- Your app must be signed with a Developer ID Application certificate.
- Hardened Runtime enabled (a security feature).
electron-builder handles most of these configurations for you.
Notarizing with electron-builder
electron-builder simplifies the notarization process. You configure your Apple ID credentials and it handles uploading your app to Apple's notarization service.
It waits for the notarization to complete and then "staples" the notarization ticket to your app bundle.
{
"build": {
"mac": {
"hardenedRuntime": true,
"gatekeeperAssess": false,
"entitlementsInherit": "build/entitlements.mac.plist",
"entitlements": "build/entitlements.mac.plist"
},
"afterSign": "electron-builder-notarize"
}
}Secure & Automated Signing
Always keep your signing certificates and private keys secure. Treat them like sensitive passwords.
Integrate code signing and notarization into your Continuous Integration/Continuous Deployment (CI/CD) pipeline to automate the process and ensure every build is properly signed and notarized.
Check Your Knowledge
Which statements accurately describe the purpose or requirements of code signing and macOS notarization?
Recap: Trust & Security
In this lesson, we learned about the critical role of code signing for Windows and notarization for macOS in distributing your Electron applications.
These processes build user trust, ensure app integrity, and help your app run smoothly on target operating systems by satisfying their built-in security requirements.
Perguntas Frequentes
A aula “Assinatura de Código e Notarização” é grátis?
Sim — o texto completo de “Assinatura de Código e Notarização” é grátis para ler aqui na web. Para praticá-la interativamente (um editor de código integrado e um tutor de IA 24/7) e desbloquear o restante do curso de Electron Desktop App Development, atualize para CoddyKit PRO. O curso de Electron Desktop App Development inclui 4 aulas no total.
O que vou aprender em “Assinatura de Código e Notarização”?
Entenda a importância da assinatura de código para Windows e da notarização para macOS, garantindo a confiança dos usuários e a conformidade com os requisitos de segurança. Você pratica Electron Desktop App Development com código prático que executa diretamente no navegador, e um tutor de IA 24/7 responde suas dúvidas enquanto trabalha na aula.
Preciso ter experiência prévia para começar Electron Desktop App Development?
Nenhuma experiência prévia é necessária. Electron Desktop App Development no CoddyKit é estruturado para alunos iniciantes até avançados, então você pode começar aqui ou desde o início e aprender no seu ritmo. Esta é a aula 2 de 4.
Quanto tempo leva a aula “Assinatura de Código e Notarização”?
A maioria das aulas CoddyKit leva cerca de 5–10 minutos. Cada uma é compacta e interativa, então você faz progresso constante e retoma exatamente de onde parou entre web e app.
Posso escrever e executar código nesta aula de Electron Desktop App Development?
Sim. Cada aula de Electron Desktop App Development inclui um editor de código integrado, então você escreve e executa código real direto no navegador e recebe feedback de IA instantaneamente — nenhuma configuração local necessária.
Todas as aulas deste curso
- Empacotamento Multiplataforma
- Assinatura de Código e Notarização
- Distribuição por Lojas de Aplicações
- Automatizando Versões com CI/CD