Apple verification
Release builds are Developer ID signed, submitted to Apple notarization, and stapled before public distribution.
Security
CommandSmith treats the server as a distribution channel, not as the root of trust. Updates must still verify against Apple signing and Sparkle signatures.
Release builds are Developer ID signed, submitted to Apple notarization, and stapled before public distribution.
The appcast points to EdDSA-signed update archives. The private signing key should stay on the release Mac or protected CI, never on the server.
commandsmith.app serves immutable DMGs, appcasts, release notes, and manifests. Compromise of static hosting should not be enough to ship a valid update.
Build, sign, notarize, generate the Sparkle appcast, then upload public artifacts. Keep Developer ID credentials, Apple API keys, SSH deploy keys, and Sparkle private keys out of the website container and out of the release host.
Versioned DMGs and delta files can be cached for a long time. The appcast and latest manifest should stay short-lived so users receive update availability quickly.