Security fixes are provided for the latest published release.
Please use GitHub's private vulnerability reporting feature for this repository. Do not disclose a suspected vulnerability in a public issue.
Signing certificates, .p12 files, App Store Connect keys, passwords, and
notarization credentials must never be committed. Public releases are valid
only when their SHA-256 checksum matches the checksum attached to the GitHub
Release and Gatekeeper reports that the DMG is accepted.