## Context We have an Apple developer account set up. macOS binaries need to be signed and notarized so users don't hit Gatekeeper warnings. ## Tasks - [ ] Add codesigning step to the release workflow for macOS binaries - [ ] Notarize binaries with Apple's notarization service - [ ] Store signing credentials (certificate, password, Apple ID, team ID) as GitHub Actions secrets - [ ] Verify signed binaries pass `spctl` and Gatekeeper checks