Skip to content

Releases: ahmetbsbnr/coretend

CoreTend 0.9.1-rc.5

CoreTend 0.9.1-rc.5 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 13:44
efccece

CoreTend 0.9.1-rc.5 (release candidate)

This release candidate supersedes 0.9.1-rc.4. It is not a stable 1.0, and
rc.4 remains unchanged in the release history.

Review, confirm, then use the Trash

The former Dry Run product mode has been removed from the application, public
site, documentation and deterministic product fixture. Scanning remains
read-only. Cleanup, Smart Care, Duplicates, Applications, Leftovers, Privacy
Cleaner and Space Lens now show the reviewed selection and require explicit
confirmation before eligible items move to the macOS Trash. SafetyCore still
re-validates every approved path immediately before execution, protects system
roots and rejects symlink escapes.

The local database migration removes the retired preference. Old database
columns and rows are retained only for downgrade/data compatibility and are
not exposed by the current product API.

This release also normalizes the public English and French locale URLs to
/en and /fr, fixes the narrow Workflow layout, and keeps Support, release
metadata and downloads generated from one reviewed release record.

Distribution status

This Apple-silicon build is ad-hoc signed, has no Developer ID signature and is
not notarized. Copy CoreTend to /Applications, try opening it once, then use
System Settings → Privacy & Security → Open Anyway. Never disable
Gatekeeper globally or remove quarantine recursively. Developer ID signing and
notarization are planned for a later distribution update. CoreTend is not
currently available from the Mac App Store; an App Store edition remains only
a future study.

IntegrityCore remains the current read-only integrity implementation. The
retired ClamAV interface, process wrapper and scanner are not present.

CoreTend 0.9.1-rc.4

CoreTend 0.9.1-rc.4 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 02 Aug 10:43
67bb2e5

Manifest clarification / Précision sur le manifeste

The immutable latest.json asset retains two conservative sentences inherited from an older template: it says the DMG has no saved icon positions and that the full visual campaign could not run. Those two sentences do not describe rc.4. The deterministic DMG layout, including icon positions, was validated; 79 reviewed public-site captures and exact-DMG bilingual light/dark app captures were completed. The asset remains byte-for-byte unchanged so its published checksum, Minisign signature and provenance stay valid.

L’asset immuable latest.json conserve deux phrases prudentes héritées d’un ancien template : il indique que le DMG n’a pas de positions d’icônes enregistrées et que la campagne visuelle complète n’a pas pu être exécutée. Ces deux phrases ne décrivent pas rc.4. La mise en page DMG déterministe, positions d’icônes comprises, a été validée ; 79 captures publiques relues et les captures bilingues clair/sombre de l’app extraite du DMG ont été réalisées. L’asset reste strictement inchangé afin de préserver son empreinte, sa signature Minisign et sa provenance.


English

CoreTend 0.9.1-rc.4 (release candidate)

This release candidate supersedes 0.9.1-rc.3. It is not a stable 1.0.
rc.3's files are left exactly as they were published — replacing them would
break any checksum already recorded — and this is a new build from the
current source.

ClamAV is gone. Integrity replaces it.

Earlier builds, including rc.3, shipped a Protection tab that wrapped a
user-installed clamscan (ClamAV) binary. Using it required opening
Terminal and running brew install clamav, which broke this project's own
rule for every feature: never Terminal, never Homebrew. Building a proper
in-app installer for a third-party GPL-2.0 scanning engine was a real
distribution and licensing undertaking this project had not had legal
review for, so the feature was retired rather than shipped as a
Terminal-dependent version of itself. Full rationale in
Documentation/CLAMAV_DECISION.md.

In its place, the Protect sidebar destination's first tab is now
Integrity, powered by the first-party IntegrityCore: three read-only checks against signals macOS already
records — download provenance, code-signature tier, and login items. No
scanning engine, no signature database, no third-party binary, nothing
downloaded, nothing running in the background. It is explicitly not an
antivirus and does not claim to be one — see
Documentation/PROTECTION_LIMITATIONS.md
for exactly what it does and does not tell you.

This is a real behavior change, not a rename: the old quarantine folder,
the ClamAV process wrapper, and the background watcher that triggered scans
on new files are all gone from the source tree, not just hidden from the
UI.

Still true

Ad-hoc signed only and not notarized: this build has no Developer ID
signature, so Gatekeeper will block the first launch. Copy CoreTend to
/Applications, double-click once, then use System Settings → Privacy &
Security → Open Anyway
(Control-click → Open still works on macOS 14).
Never disable Gatekeeper and do not run a blanket quarantine-removal
command. Minisign signatures and the provenance attestation, when present,
prove the files came from this repository's workflow; they are not
Apple code signing and not notarization. Apple silicon, macOS 14 or
later. Developer ID signing and notarization are planned for a later
distribution update. CoreTend is not currently available from the Mac App
Store; an App Store edition remains only a future study.


Français

CoreTend 0.9.1-rc.4 (version candidate)

Cette version candidate remplace la 0.9.1-rc.3. Ce n'est pas une 1.0 stable.
Les fichiers de rc.3 restent exactement tels qu'ils ont été publiés —
les remplacer casserait toute empreinte déjà relevée — et ceci est une
nouvelle compilation depuis la source actuelle.

ClamAV a disparu. Integrity le remplace.

Les versions précédentes, y compris rc.3, embarquaient un onglet Protection
qui encapsulait un binaire clamscan (ClamAV) installé par l'utilisateur.
L'utiliser exigeait d'ouvrir Terminal et de lancer brew install clamav,
ce qui enfreignait la règle de ce projet pour chaque fonctionnalité :
jamais de Terminal, jamais de Homebrew. Construire un véritable
installeur intégré pour un moteur de scan tiers sous licence GPL-2.0
représentait un vrai chantier de distribution et de conformité juridique
que ce projet n'avait pas fait valider ; la fonctionnalité a donc été
retirée plutôt que livrée sous une forme dépendante de Terminal. Le
raisonnement complet se trouve dans
Documentation/CLAMAV_DECISION.md.

À sa place, le premier onglet de la destination Protect de la barre
latérale est désormais Integrity, alimenté par le composant interne
IntegrityCore : trois contrôles en lecture seule
sur des signaux déjà enregistrés par macOS — provenance de téléchargement,
niveau de signature de code et éléments de connexion. Aucun moteur de
scan, aucune base de signatures, aucun binaire tiers, rien à télécharger,
rien qui tourne en arrière-plan. Ce n'est explicitement pas un antivirus
et cela ne prétend pas l'être — voir
Documentation/PROTECTION_LIMITATIONS.md
pour savoir précisément ce que cet onglet indique et ce qu'il n'indique pas.

C'est un vrai changement de comportement, pas un simple renommage :
l'ancien dossier de quarantaine, l'encapsulation du processus ClamAV et le
surveillant en arrière-plan qui déclenchait les analyses sur les nouveaux
fichiers ont tous disparu du code source, pas seulement de l'interface.

Toujours valable

Signé ad hoc uniquement et non notarisé : ce build n'a aucune signature
Developer ID, donc Gatekeeper bloquera le premier lancement. Copiez CoreTend
dans /Applications, double-cliquez une fois, puis utilisez Réglages
Système → Confidentialité et sécurité → Ouvrir quand même
(le clic droit
→ Ouvrir fonctionne toujours sur macOS 14). Ne désactivez jamais
Gatekeeper et n'exécutez pas de commande globale de suppression de
quarantaine. Les signatures Minisign et l'attestation de provenance,
lorsqu'elles existent, prouvent que les fichiers proviennent du workflow
de ce dépôt ; ce n'est pas la signature de code Apple ni la
notarisation. Apple silicon, macOS 14 ou ultérieur.
La signature Developer ID et la notarisation sont prévues pour une future
mise à jour de distribution. CoreTend n'est actuellement pas disponible sur
le Mac App Store ; une éventuelle édition App Store reste seulement une
étude future.

CoreTend 0.9.1-rc.3 (superseded)

Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Jul 10:02

Superseded / Remplacée

This release remains available for historical verification, but 0.9.1-rc.4 is now the recommended release candidate. Its original files and checksums are unchanged.

Cette release reste disponible pour la vérification historique, mais 0.9.1-rc.4 est désormais la version candidate recommandée. Ses fichiers et empreintes d’origine restent inchangés.


CoreTend 0.9.1-rc.3 (release candidate)

This release candidate supersedes 0.9.1-rc.2. It is not a stable 1.0.

Why rc.3 exists. Two defects made the rc.2 download unusable for someone
installing CoreTend for the first time. rc.2's files are left exactly as they
were published — replacing them would break any checksum already recorded —
and this is a new build from the current source.

The first launch now has a route that works

CoreTend is unsigned and not notarized, so macOS blocks it the first time. That
has always been true and is expected: no Apple Developer identity exists for
this project.

What was broken is the way out. Every instruction we published — the site, the
README, the install guide — told you to Control-click the app and choose
Open. Apple removed that override in macOS 15 Sequoia. On macOS 15 and
later it silently does nothing, so the app appeared to be simply broken, with
no documented way forward. That is the reported "it did not work on another
Mac", and it was a documentation defect, not a crash.

The correct route is now everywhere:

  1. Copy CoreTend to /Applications and double-click it once. macOS blocks it —
    this is expected, and it is what makes the next step appear.
  2. Open System Settings → Privacy & Security, scroll to Security, and
    choose Open Anyway. Confirm with Touch ID or your admin password.
  3. Once per copy is enough.

On macOS 14 and earlier, Control-click → Open still works.

Never disable Gatekeeper, and do not run a blanket quarantine-removal command.
The per-app step above is all that is needed.

The installer window looks like an installer again

The DMG shipped without its .DS_Store, so the volume opened as a plain Finder
window: no background, no icon placement, and three loose licence files to read
past. The window layout was being written by driving the Finder over
AppleScript, which needs an Automation permission a build cannot assume — and
when that permission was missing, the build only warned and published anyway.

  • The layout is now generated deterministically, with no Finder, no
    AppleScript, no Automation grant and no graphical session. It builds the same
    way locally, in a non-interactive shell and in CI.
  • A DMG without its layout fails the build. There is no opt-out.
  • The background is redrawn on the same paper/ink/cobalt palette as the
    website, and ships at both standard and Retina resolution.
  • The volume now contains exactly two visible items: CoreTend.app and the
    Applications shortcut. The licence texts moved inside the app bundle.

Verification and testing

  • The mounted image is checked on every release: background and both
    resolutions, window bounds, view style, icon size, both icon coordinates, no
    stray visible files, licence texts sealed inside the bundle with the
    signature intact.
  • The DMG is built from a clean clone with the Finder quit on every push.
  • 37 launch-robustness cases run under a fully isolated HOME and store: missing
    and unwritable directories, empty/truncated/corrupt preferences and database,
    ClamAV absent or broken, no network, invalid update manifests, Unicode and
    emoji and very long paths, symlink cycles, unreadable trees, 3000 files,
    relaunch after a hard kill during startup, plus 50 cold launches and 50
    launch/quit cycles.

Still true

Unsigned and not notarized. Minisign signatures and the provenance attestation
prove the files came from this repository's workflow; they are not Apple
code signing and not notarization, and they do not stop Gatekeeper from
blocking the first launch. Apple silicon, macOS 14 or later.

CoreTend 0.9.1-rc.2

CoreTend 0.9.1-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Jul 21:51

CoreTend 0.9.1-rc.2 (release candidate)

This release candidate supersedes 0.9.1-rc.1. It is not a stable 1.0.

Why rc.2 exists. The rc.1 artifacts were built before the work below
landed, so the binaries published under that tag did not contain it. Rather
than replace rc.1's files — which would have broken every checksum anyone had
already recorded — rc.1 is left exactly as it was published, and this is a new
build from the current source.

New in this build

  • Check for Updates, in Settings and in the app menu (Cmd-Shift-U). It
    reports the installed version, the latest published version and its notes,
    and opens the official release page. It never downloads or installs an
    update
    : see below.
  • Stable and prerelease channels are separated. A stable user is never
    offered a release candidate, even a newer one. Automatic checking is off
    by default
    and opt-in.
  • A trust section on the website where every claim links to the evidence,
    and a Verify your download page in both languages.
  • The release itself is now built by a workflow from the tag, and ships a
    provenance attestation, an SPDX SBOM, SHA-256 checksums and Minisign
    signatures.

Why the app will not update itself

Installing an update means running code fetched from the network, which is
only safe if the publisher can be proven. A SHA-256 checksum published beside
the file it describes proves the download was not corrupted; it proves nothing
about who produced it, because anyone able to replace the artifact can replace
the checksum too. These builds also carry no Apple Developer ID.

So the app does the honest subset: it tells you a version exists, shows you
what changed, and sends you to the official release page to download and
verify it yourself. CoreTend remains fully functional offline; the check is
optional and asks first.

Verifying this release

Four independent checks, weakest to strongest — each answers a different
question and none replaces the others:

  1. SHA-256 — the file arrived intact. shasum -a 256 -c SHA256SUMS
  2. Minisign — the file was signed by CoreTend's release key.
    minisign -Vm <file> -P RWQwtx2esD9H+O7kDWTJcdyTfcWYkmnRMqlDrk0L8xHZkSk4lA6rZqSg
    (key ID F8473FB09E1DB730, also published as minisign.pub)
  3. Provenance attestation — this exact file was produced by this
    repository's release workflow from a named commit.
    gh attestation verify <file> --repo ahmetbsbnr/coretend
  4. Build it yourselfDocumentation/BUILDING.md, tested end to end.

Minisign is not Apple code signing and not notarization. It proves the
release key signed the file. It does not make macOS trust the app.

Still true, and stated plainly

Unsigned and not notarized. security find-identity -v -p codesigning
reports zero valid identities on the build machine, because a Developer ID
requires a paid Apple Developer Program membership this project does not have.
macOS will refuse to open the app on first launch, and that warning is
accurate.

Two official ways to open it anyway, both of which keep every system
protection in place:

  • Control-click (or right-click) CoreTend in Finder, choose Open, confirm.
  • Or System Settings → Privacy & Security, find the blocked-app message,
    choose Open Anyway.

Never disable Gatekeeper to install this. Nothing here is worth turning
off a system-wide protection, and nothing in this project will ever ask you
to.

The trademark watch item on COREXTEND is unresolved and legalReviewStatus
remains pending. No legal or trademark clearance is claimed.

CoreTend 0.9.1-rc.1 (release candidate)

Pre-release

Choose a tag to compare

@ahmetbsbnr ahmetbsbnr released this 28 Jul 13:00

CoreTend 0.9.1-rc.1 (release candidate) — Not a 1.0

This is a release candidate, not a stable 1.0. It follows 0.9.0 with a set of
concrete fixes and no feature changes. It carries the same disclosures as
0.9.0 below, plus one new one.

Why this isn't 1.0

The COREXTEND trademark watch item recorded in
Documentation/CORETEND_TRADEMARK_SCREENING.md is unresolved, and
legalReviewStatus in Documentation/PROJECT_STATE.json remains pending.
No legal or trademark clearance is claimed for this build. A stable 1.0 is
withheld until that review concludes.

What changed since 0.9.0

  • Fixed a flash of unstyled content (default blue links, no styling) on the
    website's language-splash page. The first fix used inline CSS/JS, which
    the site's own Content-Security-Policy would have silently blocked in
    production — caught and corrected before release.
  • Fixed swift test failing on machines without Xcode.app installed
    (no such module 'Testing') by declaring swift-testing as an explicit,
    pinned dependency. Test-target only — no change to the shipped app.
  • Fixed the ClamAV onboarding step's "Recheck" button, which could never
    detect a ClamAV binary installed mid-onboarding. Added a "Copy Install
    Command" button alongside it.
  • Fixed Scripts/test-uninstall.sh, which targeted the real
    /Applications/CoreTend.app regardless of its test fixture's fake home
    directory — a real install could have been deleted by running this test.
    Now fully isolated.

Still true from 0.9.0

CoreTend is not signed and not notarized. security find-identity -v -p codesigning reports zero valid identities on the build machine — signing
requires a paid Apple Developer Program membership this project does not
have. The app is simply unsigned, and says so.

macOS will refuse to open it on first launch. Right-click (or
Control-click) CoreTend in Finder and choose Open, then confirm. Do this
once. Full instructions, including how to verify the download's SHA-256
first, are in Documentation/INSTALL_UNSIGNED.md.

Do not disable Gatekeeper to install this.

Verify what you downloaded before opening it: compare its SHA-256 against
the one published alongside this release with shasum -a 256 <file>.

CoreTend 0.9.0 — Public Beta (arm64, unsigned)

Choose a tag to compare

@ahmetbsbnr ahmetbsbnr released this 27 Jul 15:32

CoreTend 0.9.0 (public beta) — First Public Release

This is the first release of CoreTend available to anyone. It is a beta,
and it is unsigned. Both of those words are meant literally; what follows
explains exactly what they cost you.

Read this before you install

CoreTend is not signed and not notarized. security find-identity -v -p codesigning reports zero valid identities on the build machine, because
signing requires a paid Apple Developer Program membership that this project
does not have. Nothing here is a workaround for that — the app is simply
unsigned, and says so.

The practical consequence: macOS will refuse to open it on first launch.
Gatekeeper will tell you the app "cannot be opened because the developer
cannot be verified." That warning is correct. macOS cannot verify the
developer, because no developer identity was attached.

To open it anyway, right-click (or Control-click) CoreTend in Finder and
choose Open, then confirm. Do this once; macOS remembers the decision for
that copy. Full instructions, including how to check the download's SHA-256
first, are in Documentation/INSTALL_UNSIGNED.md.

Do not disable Gatekeeper to install this. Nothing about this app is worth
turning off a system-wide protection, and the per-app step above is enough.

Verify what you downloaded before opening it. Each artifact's SHA-256 is
published with the release; compare it with shasum -a 256 <file>.

What it does

CoreTend is a local macOS maintenance tool. It finds reclaimable disk space,
duplicate and similar files, large and old files, leftover files from
uninstalled apps, browser caches, and cloud-storage usage, and it reports what
it finds.

It runs entirely on your Mac. No telemetry, no analytics, no account, no
network calls
for its own purposes. There is nothing to sign up for.

Safety model

The parts that can delete are deliberately narrow, and most of the app cannot
delete at all.

  • Large & Old files, Similar Images, and Space Lens have no deletion path.
    They reveal in Finder and Quick Look. Nothing there can be removed by the
    app, automatically or otherwise.
  • Deletion goes to the Trash, through a safety layer that validates every
    path before acting. It is recoverable by design.
  • Duplicates never lose the keeper. The shallowest copy is retained and
    cannot be fully deselected, and any copy modified on disk since the scan is
    dropped from the selection before anything is trashed.
  • The browser cleaner is cache-only. It touches only files under
    Library/Caches, enforced by a path validator scoped to that directory, and
    only while the browser is closed. History and cookies are measured and
    shown
    for transparency and are never deleted.
  • Automatic actions are limited to reversible, low-risk findings. Anything
    else waits for you.

Known limitations

  • Unsigned and not notarized (above). This is the largest one.
  • Built and tested on a single Mac — one Apple Silicon machine, one macOS
    version. There is no multi-hardware or multi-OS verification, and no claim of
    any.
  • Interactive VoiceOver was not verified. Accessibility work was done at the
    code level and is real, but the build environment has no display session, so
    the interactive screen-reader pass could not be run. It is not claimed as
    verified. See Documentation/VISUAL_QA.md.
  • The DMG has no saved icon positions. Writing them needs the Finder, which
    refused automation in the build environment. Drag-and-drop installation works
    regardless; the background and volume icon are present.
  • ClamAV is optional and installed separately. When present, CoreTend flags
    findings for your review. It does not quarantine anything on its own.
  • Trademark review is not complete. Screening found no mark containing
    "coretend" across roughly 141.8 million records on TMview, but COREXTEND
    (MIPS Tech, live in class 9) is one letter away and is tracked as a watch
    item. That is not a bar to a free beta; it does require attorney review
    before any filing or commercial use.

Requirements

macOS 14.0 or later, Apple Silicon (arm64). There is no Intel build.

Source, licence, and reporting

CoreTend is open source under Apache-2.0:
https://github.com/ahmetbsbnr/coretend

Report a security vulnerability privately through GitHub private vulnerability
reporting:
https://github.com/ahmetbsbnr/coretend/security/advisories/new

Please do not open a public issue for a vulnerability. Public issues are for
non-sensitive bugs and feature requests.

Verification for this release

296 tests in 58 suites pass. Debug and Release both build clean. Artifact
checksums, the source commit, and the build's tree state are recorded in the
release manifest generated alongside the artifacts.