Skip to content

holzBar v0.0.6

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 04 Oct 06:58
e3b8022

holzBar 0.0.6

The biggest update since the fork, now stable: a new name and identity, a modern code base without a single dependency, the best features of Thaw, fixes for the bugs of the original Ice that people hit most, five languages and a security audit. Releases are now signed with holzBar's own certificate and carry a build provenance attestation, so macOS keeps the Accessibility permission across updates. Read "Install and update" below before you install it. (As with every release before 1.0, GitHub marks it as a pre-release.)

✨ Highlights

  • holzBar is holzBar everywhere. New bundle identifier com.holzcloud.holzBar, app holzBar.app, URL scheme holzbar://, and the bar below the menu bar is now the holzBar Shelf. Settings of the original Ice (layout, hotkeys, appearance) are still imported on the first launch.
  • The bugs of Ice that hurt most are solved. Empty layout editor and Shelf on macOS 26, items that cannot be moved, a stuck pointer, a menu bar look in the wrong place, the split shape on ultrawide displays, the volume and brightness HUD, and high CPU, energy and memory: all confirmed solved on a Mac. See Fixed.
  • Built with Swift 6.4 and Xcode 27 (macOS 27 SDK), in Swift 6 language mode with data-race safety checked by the compiler, @Observable instead of Combine, one backend per macOS generation.
  • Zero dependencies. holzBar links no third-party package; every line that runs is in this repository.
  • Never online, least privilege. A CI check proves there is no network code in the app. Only Accessibility is asked at the first launch; Screen Recording only when a feature needs it.
  • Thaw's best features: Zen mode, Shortcuts actions, profiles bound to a display or a Space, opening an item by letter, and more (see New).
  • Releases you can verify. Signed with holzBar's own certificate and attested by GitHub, so you can check that a download is what this repository built.
  • Five languages: English, German, French, Italian and Romansh.
  • Checked on macOS 14, 15, 26 and 27: every pull request launches the app on each of them and runs the 371 unit tests.

🆕 New

  • Zen mode — one hotkey, menu item, URL or Shortcuts action keeps hidden items hidden; optionally on by itself while the screen is mirrored or shared, without any permission.
  • Shortcuts actions — Toggle Zen Mode, Change Section, Apply Layout Profile, Open Menu Bar Item (by name) and Search Menu Bar Items.
  • Hotkeys per layout profile and per menu bar item.
  • Profiles bound to a display or a Space — applied when you connect the display or switch to the Space.
  • Open an item by letter — a hotkey shows a letter under every item; type it to open the item's menu.
  • Keyboard and VoiceOver — arrange items in the Layout pane with the arrow keys, undo with ⌘Z, move items with VoiceOver actions; the holzBar Shelf works with the arrow keys, Return and Escape.
  • Opened items stay up to 30 s after their menu closes, or open without showing the item at all.
  • Show When It Changes — an item you mark shows for 5 s when its title or value changes.
  • Folders with their own colour and symbol, and item images of your choice; without Screen Recording, the holzBar Shelf and the search show app icons.
  • Dashed and dotted borders, tints from the wallpaper or the accent colour, and the system's glass (glass on macOS 26 and later).
  • Settings sync through any folder your Macs sync — iCloud Drive, Nextcloud, Dropbox, OneDrive, Syncthing or a network share. holzBar only reads and writes holzBar/Settings.plist there and notices changes when the folder delivers them, with no polling.
  • Typo-tolerant search — find items by abbreviation ("cc" for Control Centre) and despite a typo, with holzBar's own code instead of a library.
  • Translations — holzBar follows your Mac's language; choose another one for holzBar alone in System Settings → General → Language & Region → Applications.

🛠 Fixed

Problems that the original Ice has open and that holzBar now solves (confirmed on a Mac):

  • macOS 26: the layout editor and the Shelf are no longer empty ("Unable to display menu bar items").
  • Moving items no longer times out, also with Live Activities and iPhone items in the bar.
  • The pointer no longer gets stuck after you click an item in the Shelf.
  • The bar, tint and shape are drawn in the right place — on every desktop, on secondary and rotated displays, and stepping aside in fullscreen.
  • The split shape is right on ultrawide and external displays.
  • The volume and brightness HUD works again on macOS 26.
  • Much less CPU, energy and memory: no polling where macOS sends an event, input taps and timers only while something needs them, images released when unused.

And more:

  • Turning on settings sync no longer crashes holzBar. Beta 1 crashed when you chose a sync folder, and then at every launch because sync stayed on. The sync folder is now watched on the queue macOS calls it on.
  • The Dock icon goes away after the permissions window, also when it was closed with its close button or while System Settings was in front.
  • Input never stalls when another app hangs — show on click, hover and the menus no longer wait for an unresponsive app.
  • Items keep their section after a restart, an app update, a title change or a display change, and several items of one app (OneDrive, …) are no longer mixed up.
  • Auto-rehide waits only for a real menu, never forever behind another window.
  • No Dock icon appears while showing items or opening the settings or the search.
  • The menu bar look survives sleep, wake, login and fullscreen.
  • holzBar rests while the screen is locked or the Mac sleeps and settles after waking.
  • Applying item spacing relaunches every affected app and waits for it to quit instead of killing it.
  • Hotkeys macOS cannot register (Option alone, Option and Shift alone on macOS 15 and later) are refused with an explanation.
  • macOS 27: hovering and clicking items on a second display opens their menus; holzBar's icon stays out from under the notch; items folded beside the notch come back on a wider display; no screen-recording indicator when items are shown or hidden; a click on the clock no longer flashes hidden items; apps launched while items are hidden no longer get a squashed item.
  • macOS 26: clicks in the holzBar Shelf are reliable again.
  • The full list of the original Ice's bug reports that holzBar fixes is in docs/upstream-bugs.md.

🔄 Changed

  • New identity. Because the bundle identifier changed, macOS treats holzBar as a new app if you come from 0.0.5: you grant Accessibility again (and Screen Recording, if you use it), and turn "Launch at login" on again.
  • Screen Recording is asked only in context — the first time you open the holzBar Shelf, the search or the Menu Bar Layout pane, or choose a menu bar shape with a moving wallpaper. Never at launch.
  • URL commands and Raycast toggles ask first. holzbar://shelf/toggle, holzbar://auto-rehide/toggle and holzbar://profile/<name> change settings that last and sync, so holzBar asks before it acts. The Raycast script commands use these URLs and ask too. Shortcuts actions run without the question, because you built the shortcut yourself.
  • holzbar://zen/on, /off and /toggle — a URL can always turn Zen mode on; turning it off asks first.
  • Ice settings are migrated in one step while they are imported, instead of a migration chain at every launch.
  • Leaner: no mouse tracking unless show on hover is on, no timers or polling while nothing is shown, item images released when unused and kept in Caches (excluded from backups).
  • No runtime patching of AppKit (method swizzling) any more.
  • Signed with holzBar's own certificate, with a build provenance attestation (see Install and update).

🔒 Security

holzBar had a full security audit before this release; the threat register is in SECURITY.md.

  • URL commands cannot end Zen mode behind your back. Any app, or a web page once your browser has asked, can open a holzbar:// URL. Turning Zen mode off by URL now asks, and is refused while Zen mode is on because the screen is shared; while Zen mode is on, no URL reveals hidden items or changes a setting.
  • Questions cannot be spoofed or repeated. They name only profiles you saved, never text from the URL; one question is open at a time, and after you cancel one, holzBar ignores such commands for 30 seconds.
  • Imported and synced settings are range-checked. A single out-of-range number in a settings file could crash holzBar at every launch, and a stored hotkey without a modifier could take that key system-wide. Numbers are now clamped or refused, and hotkeys without a modifier are not loaded.
  • Importing a settings file cannot turn settings sync on, and the sync file no longer carries your computer's name.
  • The sync file is read defensively: no symbolic links, at most 1 MB, files dated far in the future ignored.
  • Custom icons are decoded only as bitmaps (PNG, JPEG, TIFF, HEIC, GIF, BMP or ICNS) with size limits, in the process that holds Accessibility.
  • Scripts/install.sh builds in a private temporary folder instead of a fixed path in /tmp.
  • The menu bar item service accepts only holzBar's own code. holzBar's builds carry no Apple team, so the service checks the signing identifier and the exact code hashes of the app it is embedded in, and refuses every other process.
  • A stable signature and build provenance. Every release is signed with the same certificate, so a replaced holzBar.app signed with another key does not inherit the Accessibility permission, and gh attestation verify proves that a zip was built by this repository's release workflow.

⚠️ Known issues

  • macOS 27 hides the privacy indicator while holzBar hides items. While holzBar hides any menu bar item on macOS 27, Control Centre does not show its indicator for the camera, the microphone and screen recording; the small green dot beside the clock still shows the camera. It comes back while holzBar hides no item. holzBar cannot prevent it; Settings → General says so too.
  • On macOS 27, items can't be reordered on the bar itself, only assigned to sections, and opening a system item (clock, battery, Wi-Fi) while hidden items are concealed adds about 150 ms.
  • holzBar has no Apple Developer ID and is not notarized, so macOS may say it "can't be opened" if you download the zip yourself (the Homebrew cask takes care of it; see the quarantine command below).
  • The translations into German, French, Italian and Romansh are machine-written; corrections are welcome on the issue tracker.

📦 Install and update

holzBar runs on macOS 14 Sonoma to macOS 27, checked in CI on macOS 14, 15, 26 and 27. Quit the original Ice, Thaw, Bartender or Hidden Bar first if one of them is running: two menu bar managers must never run at the same time.

Update from 0.0.6 beta 1 or beta 2

brew update && brew upgrade --cask holzbar

This release is signed with the same certificate as the betas, so macOS keeps the Accessibility permission. If beta 1 crashed at launch because of settings sync, this update fixes it and holzBar starts again with sync on.

Update from 0.0.5

0.0.5 was published under the app's former name, as a different cask and a different app, so brew upgrade does not replace it and holzBar does not take over its settings:

  1. To keep your layout, hotkeys and appearance, open the old app's Settings → Advanced and click Export….
  2. Quit the old app, then uninstall its cask: brew list --cask shows its name; run brew uninstall --cask with that name.
  3. Install holzBar with the three commands under "New install" below.
  4. Open holzBar, click Grant Permission in the permissions window and turn holzBar on in System Settings → Privacy & Security → Accessibility. If the window stays open, click Reset and Grant Again.
  5. Open Settings → Advanced, click Import… and choose the exported file. If the original Ice is installed, its settings are imported on the first launch anyway.
  6. Turn Launch at login on again in Settings → General: it belongs to the new app.

New install

brew tap holzcloud/holzbar https://github.com/holzcloud/holzBar
brew trust --cask holzcloud/holzbar/holzbar
brew install --cask holzbar

brew trust is needed once: Homebrew only installs casks from third-party taps that you have trusted.

If macOS says holzBar can't be opened, take it out of quarantine and open it again:

xattr -dr com.apple.quarantine /Applications/holzBar.app

Verify your download

Every zip carries a build provenance attestation. With the GitHub CLI:

gh attestation verify holzBar-0.0.6.zip -R holzcloud/holzBar

The app is signed with holzBar's own certificate, SHA-256 e55f0df15060b8c06c6842ccee85e6bc9f86cbbda3bd408abf991457840b1d95; this shows it:

codesign -dv --verbose=4 /Applications/holzBar.app

More in docs/signing.md.

Credits and license

holzBar is a fork of Ice by Jordan Baird, and nearly everything here is his work. Thank you, Jordan. Code adapted from Thaw and Barometer is listed in NOTICE. holzBar is available under the GPL-3.0 license, like Ice. Found a bug? Please tell us on the issue tracker.