It's certainly either something I'm doing wrong, or a big in the software I'm using to automate signing, notification and stapling.
Here's the issue I opened on the software I'm using to automate: https://github.com/electron-userland/electron-builder/issues... that issue kinks to the PR that adds the automation.
It's a non-trivial thing to test, since it involves so many secrets and the notarization step can take over an hour, so I don't expect anyone here to actually want to look into it.
My original comment really was just venting my frustration, not a cry for help (but I might be crying soon if I cant get to the bottom of this!).
/Applications/Ganache.app: rejected (invalid destination for symbolic link in bundle) origin=Developer ID Application: ConsenSys AG (48XVW22RCG)
I see you're also migrating to Github Actions for this particular release and that the notarization process was working correctly on your previous CI/CD? I guess there has to be an issue with the new environment here or the way you're building it now.
Conveyor can package Electron apps and also do all the Mac specific stuff from any platform including Linux. So it can sign, notarize and staple the app itself, also bundling Sparkle updates as it goes. We're listed on the Electron website these days. You may have more luck with it. There's a Discord channel for help too if you get stuck.
[1] https://hydraulic.dev/ (disclosure: my company)