The app ships an auto-updater pulling from GitHub releases. Confirm the update chain is trustworthy: - [ ] macOS builds signed + notarized - [ ] Windows builds signed - [ ] Updater verifies signatures before applying updates An unsigned auto-update channel is the most likely attack surface for a desktop app distributed this way.
The app ships an auto-updater pulling from GitHub releases. Confirm the update chain is trustworthy:
An unsigned auto-update channel is the most likely attack surface for a desktop app distributed this way.