Quinn,
Thanks for your reply and advices!
I added codesign for a DMG image. And then spctl shows that DMG is correct:
MyApp.dmg: accepted
source=Notarized Developer ID
It seems that many Mac developers (including me) were not aware that it also necessary to codesign DMG in addition to codesigning of APP bundle and notarization.
2. Probably I found a typo in your article "Testing a Notarised Product". It says:
Disk image
spctl -a -t open -vvv --context context:primary-signature WaffleVarnish.dmg
However this command shows nothing for any correctly notarized app (including my app, Chrome, Audacity, etc).
If I add "-v" to your command:
spctl -a -t open -vvv --context context:primary-signature WaffleVarnish.dmg -v
It shows a result for Chrome:
googlechrome.dmg: accepted
source=Notarized Developer ID
Topic:
Code Signing
SubTopic:
Notarization
Tags: