slock v0.2.9
In-place updates are back, without additional updater permissions or dependencies.
- Check for Updates… is always available and becomes Update slock… when
a newer stable release is known. Clicking it rechecks the latest release instead
of opening a cached, older release page. - slock downloads and verifies the update, replaces itself in the same writable
location, and relaunches. Pairings and preferences stay intact. The updater does
not request administrator or Keychain access. - Update packages require a signature from slock's dedicated Ed25519 signing key.
Only the app's fixed set of regular files can be staged; no archive extraction
or downloaded installation script is used. A failed replacement or relaunch
restores the previous app.
Upgrading from 0.2.6–0.2.8: download slock.app.zip below, quit slock,
replace the app in Applications, and reopen it once to receive the restored
updater. macOS may still require renewed keyboard permissions. SHA256SUMS
contains the ZIP's checksum; slock-update.json is used by the native updater.
This remains a prototype for macOS 13+, Apple Silicon and Intel. The app is
ad-hoc signed and not notarized. See
SECURITY.md for the
security limits and reporting guidance.