| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
Add a workflow that builds and publishes a release via GitHub Actions (#1908) The workflow assumes changelog and version information have been updated and the tag has not been created yet before running it. When the workflow finishes, it should take you to a release page with the uploaded binaries, where you can verify the final details and publish a tag officially. Also the following improvements were made: * Change CURRENT_PROJECT_VERSION to represent a monotonically increasing bundle version (starting at 2000) * Add MARKETING_VERSION to represent marketing version of Sparkle, comprised of SPARKLE_VERSION_MAJOR, SPARKLE_VERSION_MINOR, SPARKLE_VERSION_PATCH, and the new SPARKLE_VERSION_SUFFIX for pre-releases. * Verify code signing signatures of extracted SPM zip file in make release and CI * Generate changes to Sparkle podspec, just like the Package.swift file, based on current marketing version * Improve format of Info.plist version strings when appending git hash info, eliminating unnecessary whitespace * Simplify validating that XPC Service versions align with framework version * Handle lightweight tags in addition to annotated tags in release-move-tag.sh | 4 年前 | |
Reduce code size and make codebase more consistent (#2305) | 3 年前 | |
Add testing writability as part of SUInstallerLauncher This is necessary for detecting if automatic updates are possible in a sandboxed environment | 10 年前 | |
Don't copy updater progress tool app to caches directory (#2900) As part of this change, SUStatus window is now being created programmatically rather than from a nib, so the nib does not need to be loaded in the progress tool (Updater.app) nor duplicated. The localizations this helper tool needs are also now being autogenerated. In the Updater.app, since the app can be swapped, we will minimize what needs to be loaded from disk. Also, the progress Updater app is no longer brought up the from when its status window shows, which could cause it to show up as a recent app entry in the Dock. I used AI to re-generate the SUStatus window programmatically, which I've verified have same properties as the removed xib, and to create the python script to generate the localization header for the Updater app which I've reviewed. | 1 个月前 | |
Harden policy on what operations clients are allowed to take (#2763) * For the Installer and Downloader XPC Services, if these executables are code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID. * For the Downloader XPC Service, the request URL must be http/https * For Autoupdate, if stage 1 of installation hasn't been completed yet and this executable is code signed with an Apple issued Team ID, then the connecting client must also be code signed with a matching Team ID. As before, multiple simultaneous connections are still disallowed. * For Autoupdate, if it's not signed with Apple issued certificate, when installing package updates the bundle being updated must be itself and owned by root on disk (as one expects from a PKG installation) * The authorization prompt message in the Installer Service is more computed inside the service so the client can't pass a completely arbitrary message * Add extra nullable checking of parameters coming from XPC endpoints * Add more thread-safe synchronization for Autoupdate installer * Add logs for more failure points | 1 年前 | |
Don't pass installer/agent path to launcher XPC service The InstallerLauncher code now tries to locate these tools inside Contents/MacOS/ or inside the Resources directory. The installer launcher XPC service now has a copy of the tools included in its bundle. This may seem like wasting space but it enables eg, the XPC service not trusting a sandboxed application. A developer could always remove the tools from the Sparkle framework if necessary (we can't because the XPC services are optional..) Using the XPC service allows the developer to sign the installer executable (Autoupdate.app). The agent app can be moved and signed into the MacOS executables directory as well. We don't do that automatically because Xcode's tooling doesn't play nice with attempting that, although that could be looked at later. | 9 年前 | |
Remove unused connection validation options (#2783) | 10 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 4 年前 | ||
| 3 年前 | ||
| 10 年前 | ||
| 1 个月前 | ||
| 1 年前 | ||
| 9 年前 | ||
| 10 个月前 |