sparkle-project / Sparkle

A software update framework for macOS
https://sparkle-project.org
Other
7.41k stars 1.05k forks source link

Require signing validation for apple archives before extraction #2588

Closed zorgiepoo closed 3 months ago

zorgiepoo commented 3 months ago

Because .aar support is new and not a widely used format, require validating them before extraction for now (similar to delta based updates). This also means this archive format cannot presently be used for key rotation. Strengthening the validation later will be harder to do if people start to rely on the format, so better to try this now than later.

Related to #2586

Misc Checklist

Testing

I tested and verified my change by using one or multiple of these methods:

Tested aar extraction only works when updating aar archived app when signature is valid with sparkle-cli Tested policy for updating zipped based app is still the same (more lax).

macOS version tested: 14.5 (23F79)