|
|
|
|
|
by CGamesPlay
214 days ago
|
|
The linking step isn't even required. You can download any existing binary and codesign it yourself with your local developer certificate. You can even overwrite the existing signature. I assume brew could even automate this, but are choosing not to for whatever reason. |
|
If the homebrew team signed everything, they would immediately become a target for bad actors. The bad actors would flood homebrew with malicious binaries, which homebrew would auto-sign, users would download & run, and the bad actors would laugh all the way to the bank.