Skip to content
Snippets Groups Projects
Unverified Commit 1ca60d5a authored by Zorg's avatar Zorg Committed by GitHub
Browse files

Add option to verify updates before extraction (#2667)

Adds an opt-in option (SUVerifyUpdateBeforeExtraction) to enforce verifying updates before extracting them for stronger security. EdDSA signing is required to use this option. As fallback in case EdDSA keys are lost, disk image archives's code signatures are validated assuming it's Developer ID signed. Key rotation is still possible.

Apple Archives (aar, yaa) now require using this option.
parent 597825d1
Loading
Showing
with 410 additions and 61 deletions
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment