Is there a reason the OSX binary needs to be signed? We don't do anything special.
Edit: HTTPS up: https://servo-builds.s3.amazonaws.com/index.html
(This comment written in Servo :P )
In the latest Sierra beta I've heard you can't disable the check without an involved workaround.
It's just OSX users being lazy ;)
Can it be signed by any old cert or does it need to be part of the trust chain?
Here's the relevant tracking issue for the same problem in Rust.
Outside of that, Gatekeeper applies to executables fetched from the Web, can be disabled (harder on Sierra), and is easy enough to bypass--and you only have to do it once per executable. If signed, the certificate does need to be trusted to count--otherwise, it'd just be a fancy checksum.
Windows 10 has a similar feature.
It's unfortunate that a LetsEncrypt style project can't be done for code signing, due to malware/admin overhead.
[0] https://github.com/browserhtml/browserhtml#building-and-runn...
Gatekeeper is nice in some important ways but seeing as it isn't free, I'd also be quite happy with just a SHA1 or similar signature to verify a binary with.