Flowlight 0.8.2
What's new in 0.8.2
- An update is verified before it is installed. The checksum comparison treated "no checksum published", "no line for this disk image" and "the file didn't parse" as a match — every way of not knowing was read as knowing it was right. It now requires a published checksum and refuses the download without one.
- And it has to be signed by us. The installer checked the downloaded app's version and bundle identifier — strings inside the disk image that nothing signs — and then removed the quarantine flag, which is what would have made macOS check the signature on first launch. Updates are now validated against Apple's anchor and the Team ID of the running copy: an update has to come from whoever signed the Flowlight asking for it.
- A model endpoint can't take your key over plain HTTP. A compatible hosted endpoint sent an API key and a question about your own traffic to whatever address was typed. https:// is now required, except for loopback and private addresses, where the model is running on your own machine or network.
- Credential headers are recognised by their words, not by a list. Redaction knew the common names, so X-Access-Key or a vendor's own spelling was written to disk under a promise that says API keys are never stored. Anything whose name carries key, token, secret, auth, credential, session or signature is redacted now.
Install
Signed with Developer ID and notarized by Apple.
brew install --cask xinbetween/tap/flowlightFlowlight.dmg— drag to Applications.Flowlight-0.8.2.pkg— installs to /Applications; offers to quit a running copy first.
macOS 15 or later, Apple silicon and Intel.
Full changelog: https://github.com/xinbetween/flowlight/releases
Checksums
9a6e39e41c99cdf793e061d85b2d994dcfa380da563f63b841d794f63d2c88e5 Flowlight.dmg
a4a35cde5a406c155cd372dc619c42f9261207308668af0f646738beaaf9acb6 Flowlight-0.8.2.pkg