Security

Convenient downloads without trusting the web server blindly.

CommandSmith treats the server as a distribution channel, not as the root of trust. Updates must still verify against Apple signing and Sparkle signatures.

Apple verification

Release builds are Developer ID signed, submitted to Apple notarization, and stapled before public distribution.

Sparkle signatures

The appcast points to EdDSA-signed update archives. The private signing key should stay on the release Mac or protected CI, never on the server.

Static release host

commandsmith.app serves immutable DMGs, appcasts, release notes, and manifests. Compromise of static hosting should not be enough to ship a valid update.

Operational model

Build, sign, notarize, generate the Sparkle appcast, then upload public artifacts. Keep Developer ID credentials, Apple API keys, SSH deploy keys, and Sparkle private keys out of the website container and out of the release host.

Cache model

Versioned DMGs and delta files can be cached for a long time. The appcast and latest manifest should stay short-lived so users receive update availability quickly.