Skip to content

cask/audit: refine codesign audits #20300

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 24, 2025
Merged

cask/audit: refine codesign audits #20300

merged 1 commit into from
Jul 24, 2025

Conversation

bevanjkay
Copy link
Member

  • Have you followed the guidelines in our Contributing document?
  • Have you checked to ensure there aren't other open Pull Requests for the same change?
  • Have you added an explanation of what your changes do and why you'd like us to include them?
  • Have you written new tests for your changes? Here's an example.
  • Have you successfully run brew style with your changes locally?
  • Have you successfully run brew typecheck with your changes locally?
  • Have you successfully run brew tests with your changes locally?

This PR proposes a change to use the newer syspolicy_check tool for Application codesign audit.
Also check notarization for binaries.

@Homebrew/cask the main discussion point here is whether we want to require notarization for binaries or not.

Copy link
Member

@MikeMcQuaid MikeMcQuaid left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good when Sonoma comment addressed, thanks @bevanjkay!

@bevanjkay bevanjkay force-pushed the codesign-audit-update branch from 4025457 to 68be276 Compare July 24, 2025 07:32
@bevanjkay bevanjkay enabled auto-merge July 24, 2025 07:33
@bevanjkay bevanjkay added this pull request to the merge queue Jul 24, 2025
Merged via the queue into main with commit e55cd21 Jul 24, 2025
36 checks passed
@bevanjkay bevanjkay deleted the codesign-audit-update branch July 24, 2025 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants