Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
App Trust Preview v1.2.3 released!

- Added static analysis that finds domains and URLs embedded in an app before you open it
- Added configurable limits for advanced component rows and other network references
- Made the collapsed report view more compact

1784049506103.png
 
Last edited:
App Trust Preview v1.3.0 released!

- Added options to export an analyzed app to a folder, ZIP archive, or DMG disk image.
- Added an option to install an analyzed app, including one opened from a DMG file, in the Applications folder when explicitly requested by the user.

2_APP_DESKTOP_0.png
 
App Trust Preview v1.3.1 brings more features!

- Added prominent warnings for apps that can load unvalidated third-party code or use unsigned executable memory.
- Privacy permissions now show whether they match the inspected build.
- Improved handling of downloaded apps, scripts, and executables.
- Added checks showing whether notarization tickets are attached for offline verification.
- Added a customizable "Open with other apps" report section.
- Added warnings for development builds that allow debugger attachment or use development push notifications.
- Added affected component paths to important entitlement warnings.
- Added the new security findings to exported reports and command-line results.
- Added personal notes for recording useful information about analyzed apps.
- Added an option to move a downloaded DMG to the Trash after installing its app.
- Removed irrelevant Apple's safety checks from script reports.

1785957418359.png


7_APP_DESKTOP_7.png
 

Attachments

  • 5_APP_DESKTOP_5.png
    5_APP_DESKTOP_5.png
    783.4 KB · Views: 32
Last edited:
App Trust Preview v1.4.0 brings even more features!

- Added Download history with source URLs, download application, date, file type, quarantine status, and macOS processing metadata.
- Added one-click copying of the original download URL.
- Reorganized Internet access and potential connections into one clearer section.
- Improved Technical details with relevant code-signing, Finder, and system file metadata.
- Improved DMG reports by clearly separating metadata for the disk image, extracted app, and bundled components.
- Expanded JSON, text, and CLI reports with download history and file metadata.
- Fixed incorrect whole-app quarantine claims and confusing metadata descriptions.
- Improved nested PKG extraction reliability, including packages containing symbolic links.
- Preserved existing report order and visibility preferences after the panel reorganization.

8_APP_DESKTOP_8.png
 
App Trust Preview v1.4.1 to v1.4.3
  • Fixed an issue that could prevent App Trust Preview from opening when macOS graphics diagnostics were enabled.
  • Fixed installed apps opening from a temporary read-only location, which could prevent them from updating.
  • Added Sparkle update delivery checks, including feed security and update signature verification.
  • Added secure signing timestamp checks to identify builds that may stop validating after their certificate expires.
  • Improved download history with additional source details recovered from macOS.
  • Added separate logical size and actual size on disk values.
  • Improved the minimum macOS requirement by checking the main app and its bundled components.
  • Expanded JSON, text, and CLI reports with the new findings.
  • Improved macOS compatibility reporting by separating the main app requirement from the highest requirement found among bundled components.
1788158277469.png
 
That should require Full Disk Access for App Trust Preview or the user manually selecting ~/Library/Application Support/com.apple.TCC/TCC.db & /Library/Application Support/com.apple.TCC/TCC.db
Now beside TCC.db it reads ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 as well
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.