# October 17th, 2024, Advisory Committee

**URL:** <https://forum.openrefine.org/t/october-17th-2024-advisory-committee/1841>\
**Category:** Day-to-day project operations\
**Tags:** minute-advisory\
**Created:** [October 23, 2024, 8:28pm UTC](https://forum.openrefine.org/t/october-17th-2024-advisory-committee/1841 "2024-10-23T20:28:41Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.openrefine.org/martin/32/7_2.png) [@Martin](https://forum.openrefine.org/u/Martin)\
**Post date:** [October 23, 2024, 8:28pm UTC](https://forum.openrefine.org/t/october-17th-2024-advisory-committee/1841/1 "2024-10-23T20:28:41Z")

</div>

## Attendees

- Antonin Delpeuch - Advisory Committee
- Jan Ainali - Advisory Committee
- Martin Magdinier - Project Manager

## Discussion

It was a short 10-minute meeting to coordinate on the status of the Apple Account. Martin provided the update directly in Github:

> <https://github.com/OpenRefine/OpenRefine/issues/6713#issuecomment-2421011451>
>
> Hi:
> 
> Thanks for developing and making OpenRefine available to the community.
> …
> There is an OpenRefine 3.8.2 Mac application that is not notarized correctly. The app or component was signed with an Apple-issued Developer ID certificate but does not appear to be notarized. Since the exceptions described above for the Developer ID status are not met, macOS will not allow this code to run (unless it is found to be notarized when Gatekeeper runs).
> 
> To verify if a Mac application is notarized, you can use the spctl command in Terminal. Here is the command:
> 
> \`\`\`
> spctl -a -v /path/to/application.app
> \`\`\`
> 
> For example, executing the command with OpenRefine 3.8.2 outputs...
> 
> \`\`\`
> spctl -a -v /Volumes/OpenRefine/OpenRefine.app   
> /Volumes/OpenRefine/OpenRefine.app: rejected
> source=Unnotarized Developer ID
> \`\`\`
> 
> Additional context
> 
> Here is some interesting general information to checkout and share with your macOS developer on resolving Gatekeeper problems on macOS.
> 
> Resolving Gatekeeper Problems | Apple Developer Forums:
> 
> The post titled "Resolving Gatekeeper Problems" on the Apple Developer Forums, written by Quinn "The Eskimo!" from Developer Technical Support at Apple is a comprehensive guide addressing common issues related to Gatekeeper on macOS. Gatekeeper is a security feature designed to ensure that only trusted software runs on a user's Mac, and the post focuses on helping developers troubleshoot and resolve issues that may arise in this context.
> 
> The post identifies four common Gatekeeper problems that developers may encounter:
> 
> App blocked by a dangling load command path.
> Broken code signature.
> Lack of notarization.
> Command-line tool blocked by Gatekeeper.
> For each of these issues, the post provides detailed steps and guidance on how developers can resolve them. The emphasis is on the importance of passing Gatekeeper checks to maintain customer trust and avoid potential loss of customers.
> Key points covered in the post include:
> 
> • Verification of Code Signature: Developers are advised to use the codesign tool to verify that their code is signed correctly. The post provides examples of command-line usage to check for issues such as missing or invalid sealed resources.
> • Notarization Issues: Gatekeeper requires that apps be notarized, and the post guides developers on how to identify and resolve notarization problems. It includes information on checking system logs for specific entries related to notarization issues.
> • Hash Mismatch: In cases where there's a hash mismatch, the post provides guidance based on the file type (e.g., zip archive, signed disk image, installer package) and recommends specific actions to address the problem.
> • Command-line Tool Blocking Bug: A known bug in macOS is acknowledged, where double-clicking a command-line tool in Finder may lead to it being blocked by Gatekeeper. Workarounds, such as embedding the tool in an application or using an installer package, are suggested.
> 
> Throughout the post, there are references to Apple's documentation and resources related to code signing and notarization, providing developers with additional information for a deeper understanding.
> 
> https://forums.developer.apple.com/forums/thread/706379
