Yes, but I would expect "This is an app downloaded from the internet, are you sure?", not "Ooh, this could be malware" for a signed app, surely?
If apps have to be signed AND notarized to be allowed, then why make them two separate things?
OK: Notarizing the app fixes it (though I still get the annoying "this was from the internet, are you sure" message).
Topic:
Code Signing
SubTopic:
General
Tags: