slock v0.3.0
slock now uses a persistent Developer ID signing identity so macOS can recognize
future updates as the same app.
- Releases are signed with Developer ID Application and a secure timestamp.
Later releases signed with the same identity should retain privacy approvals. - This first upgrade may require one final permission approval on each Mac.
If keyboard access is missing, follow Permissions Required; remove and
re-add an old entry if macOS still associates it with a previous build. - The native updater still verifies every package using the existing Ed25519
update key. Pairings, preferences, and the app's bundle identifier are preserved. - The release process requires Developer ID signing, preventing accidental
publication of another ad-hoc build. Signing keys can be securely transferred
to a new release Mac without changing the app's identity.
Install: use Check for Updates… in slock, or download slock.app.zip
below. Versions 0.2.6–0.2.8 need one manual app replacement to receive the native
updater. SHA256SUMS contains the ZIP's checksum; slock-update.json is used
by the native updater.
This release supports macOS 13+, Apple Silicon and Intel. It is Developer ID
signed but not notarized, so macOS may still block an initial download.
Actual permission persistence across a future signed update still needs manual
validation. See
SECURITY.md for the
security limits and reporting guidance.