sign-macos.sh signs neotalk.app with the Developer ID under the hardened runtime; release-macos.sh builds, signs, notarizes, staples and can publish the zip to the Gitea releases page. Credentials are read from the environment.
Cross-platform spec, build entry point, packaging docs, and a Gitea Actions workflow for the Windows build. Tolerate Finder-injected launch arguments.