Replace with Signed Package¶
Protection changes your artifact, which invalidates any code signature it had. The Replace with Signed Package flow lets you sign the protected build with your own certificate and upload the signed copy back to PyLocket, so the version your customers download is the trusted, signed one.
When to use it¶
Use Replace with Signed Package after you have:
- Downloaded the protected build from PyLocket.
- Signed it with your own certificate (Apple Developer ID for macOS, Authenticode for Windows). See Code Signing.
You then upload the signed file in place of the protected one. PyLocket keeps the same build, license bindings, and download links; only the bytes customers receive change to your signed version.
How to replace a build¶
- Open the Developer Portal, go to your app, and open the Builds page.
- Find the protected build and choose Replace with Signed Package.
- Select your signed file:
- Windows: the signed
.exe. - macOS: the signed
.apppackaged as.app.zip.
- Windows: the signed
- Upload. PyLocket verifies the upload is a signed copy of that exact protected build (same code, only signature data differs) and swaps it in.
It must be the same protected build, just signed
The check confirms your upload is the current protected build with a signature added, not a different or older binary. If you see a "does not appear to be a signed copy of the current protected build" message, you most likely selected an older file or a different binary. Re-download the current protected build, sign that exact file, and upload the result.
macOS: extract and re-archive with ditto, never a third-party archiver
A macOS app bundle only survives a round trip when both directions preserve symlinks, permissions, and every bundled file. Use Apple's built-in tools for both steps, from Terminal:
# 1. Extract the protected download
ditto -x -k Protected.app.zip extracted/
# 2. (sign and notarize the extracted .app)
# 3. Re-archive the signed app (keep the .app.zip name so the upload
# carries the bundle signal)
ditto -c -k --keepParent YourApp.app YourApp.app.zip
Third-party archivers can silently drop package metadata folders
(*.dist-info) from inside the bundle. So can some SIGNING tools: signing
apps that "clean" a bundle before signing have been observed deleting
*.dist-info directories outright. Those folders look inert but register
your app's plugin loaders at runtime - an app missing them still launches and
then fails only when the affected feature is used. PyLocket rejects a
replacement that lost metadata the protected build carries; the error names
the missing folders and repeats these commands.
Run this self-check twice - once right after extracting, and again AFTER signing, before you re-archive and upload:
The list must be identical both times. If entries disappear after signing,
your signing tool removed them. To recover, copy the real *.dist-info
folders back from the extracted original into
YourApp.app/Contents/Resources/, re-seal the top level of the bundle
(codesign --force --options runtime --sign "YOUR_ID" YourApp.app - the
nested signatures your tool already applied stay valid), re-run the check
above, then notarize and re-archive. Also report the deletion to the
signing tool's developers so it stops happening.
Copy the real folders, not just the shortcuts. Inside a macOS app bundle
these folders exist as real directories under Contents/Resources/ with
matching symbolic links under Contents/Frameworks/. A copy that brings
back only the links leaves them pointing at nothing, which is the same as
having no metadata at all.
The "Ready - Signed" badge¶
Once a signed replacement is accepted, the build's status on the Builds page shows Ready - Signed with a lock icon, instead of the normal Ready. This is your at-a-glance confirmation that customers are downloading a code-signed package.
A build keeps working exactly as before whether or not it is signed. The badge is purely informational; it does not change download links, license behavior, or anything your customers do.
Related¶
| Topic | Link |
|---|---|
| Sign your app | Code Signing |
| Distribute macOS apps | Distributing macOS .app bundles |
| Distribute your app | Distribute Your App |