Skip to content

Force Sparkle updater to always verify update and to use signed appcast#1638

Merged
ychin merged 1 commit intomacvim-dev:masterfrom
ychin:sparkle-force-verify-update-and-appcast-feed
Apr 7, 2026
Merged

Force Sparkle updater to always verify update and to use signed appcast#1638
ychin merged 1 commit intomacvim-dev:masterfrom
ychin:sparkle-force-verify-update-and-appcast-feed

Conversation

@ychin
Copy link
Copy Markdown
Member

@ychin ychin commented Apr 7, 2026

Sparkle 2.9 introduced the ability to verify appcast feeds using a signature. Turn that on to prevent MITM attacks.

This requires the appcast on the server side to be re-generated with signature at the end. This was done in
macvim-dev/macvim-dev.github.io#5.

Sparkle 2.9 introduced the ability to verify appcast feeds using a
signature. Turn that on to prevent MITM attacks.

This requires the appcast on the server side to be re-generated with
signature at the end. This was done in
macvim-dev/macvim-dev.github.io#5.
@ychin ychin added this to the Release 183 milestone Apr 7, 2026
@ychin ychin added the Updater Issues related to Sparkle updater label Apr 7, 2026
@ychin ychin enabled auto-merge April 7, 2026 00:02
@ychin ychin merged commit 1782e97 into macvim-dev:master Apr 7, 2026
4 checks passed
@ychin ychin deleted the sparkle-force-verify-update-and-appcast-feed branch April 7, 2026 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Updater Issues related to Sparkle updater

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant