Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Randomize the download archive name the installer extracts/executes #2584

Merged
merged 2 commits into from
Jun 16, 2024

Conversation

zorgiepoo
Copy link
Member

@zorgiepoo zorgiepoo commented Jun 15, 2024

Randomize the download archive name the installer extracts/executes for better security hardening.

Misc Checklist

  • My change requires a documentation update on Sparkle's website repository
  • My change requires changes to generate_appcast, generate_keys, or sign_update

Testing

I tested and verified my change by using one or multiple of these methods:

  • Sparkle Test App
  • Unit Tests
  • My own app
  • Other (please specify)

Need to test:

  • UUID string is not the same on subsequent runs
  • zip archives
  • tar archives
  • dmg archives
  • pkg updates
  • delta updates
  • older OS systems

macOS version tested:
14.5 (23F79)
10.14.6 VM

@zorgiepoo zorgiepoo added this to the 2.7 milestone Jun 15, 2024
@zorgiepoo zorgiepoo merged commit 007e9ae into 2.x Jun 16, 2024
2 checks passed
@zorgiepoo zorgiepoo deleted the randomize-moved-download-name branch June 16, 2024 01:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant