What to do with casks not passing the macOS Gatekeeper check? #7050
Output of
|
Replies: 5 comments 10 replies
|
Hi and thanks for your reply.
I'll think about the choices you listed - in the meantime I already notified the developer/mainainer of XLD.
What looks strange to me is that for XLD there is no new(er) version compared to the one I'm already using (which has been installed via brew). So: why does brew tell me I can't upgrade it, even though there's no upgrade available?
Thanks,
F.
…On Thursday, September 3rd, 2026 at 5:22 PM, Junaid Hussnain ***@***.***> wrote:
A disabled cask is no longer maintained as an install/upgrade path by Homebrew, so waiting will not make brew upgrade proceed automatically unless the upstream app ships a Gatekeeper-compliant build and the cask is subsequently re-enabled.
The practical choices are:
- Check the app vendor for a newer signed/notarized macOS build or a supported alternative.
- Report the signing/notarization failure upstream. That is something the app vendor must fix; it is not normally fixable in the cask definition.
- Keep the currently installed version temporarily if you accept that it will no longer receive Homebrew upgrades, or uninstall it with brew uninstall --cask <name>.
- Once upstream fixes the build, the cask can be updated/re-enabled in homebrew/cask.
I would not work around this with --no-quarantine, xattr -d com.apple.quarantine, or by disabling Gatekeeper. Homebrew policy explicitly requires macOS casks not to require Gatekeeper to be disabled or bypassed ([Acceptable Casks](https://github.com/Homebrew/brew/blob/main/docs/Acceptable-Casks.md#platform-compatibility-and-macos-security-protections)). A Gatekeeper failure is also an explicit cask deprecation reason, and disabled casks are eventually removed after one year ([lifecycle policy](https://github.com/Homebrew/brew/blob/main/docs/Deprecating-Disabling-and-Removing.md#formulae-and-casks)).
So “manage the same unsigned build manually” is technically possible only by bypassing a security control and is not the safe replacement. Prefer a vendor-fixed build or another maintained app.
—
Reply to this email directly, [view it on GitHub](#7050?email_source=notifications&email_token=AIEUZR5V7HURZRDAZR77VZD5NGSFLA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBSG4ZTINRTUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-18273463), or [unsubscribe](https://github.com/notifications/unsubscribe-auth/AIEUZR73ON4YQ4K4SLSH2535NGSFLAVCNFSNUABIKJSXA33TNF2G64TZHMZDSMRSGY3DSMJTHNCGS43DOVZXG2LPNY5TCMBXGQZTMNJWUF3AE).
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
|
I have to agree that the way this has been handled was quite unfriendly to users. I can sympathize with the team's decision not to support unsigned casks—but if the motivation there was to avoid spurious bug reports from users confused about OS warnings from unsigned apps, it feels like the way this has gone about will only create more bug reports just like this one, from users who didn't realize what was going on and now have semi-broken systems. |
|
Let me add this: I'm not trying to upgrade a specific cask, I'm just upgrading "all" and I'm notified with this: ==> Would upgrade 1 outdated package I only verified XLD's official latest version - there's no newer version. So the message above, what exactly is it triggered from? |
|
That's what I thought... but your reply was "attached" to my message... :-)
…On Friday, September 4th, 2026 at 5:21 PM, Sean Molenaar ***@***.***> wrote:
No no, I was replying to the other user who now seems banned.
—
Reply to this email directly, [view it on GitHub](#7050?email_source=notifications&email_token=AIEUZR7EMJ44D6E65DDX27L5NL22RA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCOBSHEZTENZYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-18293278), or [unsubscribe](https://github.com/notifications/unsubscribe-auth/AIEUZR7IGCWDLI243PAFJ6T5NL22RAVCNFSNUABIKJSXA33TNF2G64TZHMZDSMRSGY3DSMJTHNCGS43DOVZXG2LPNY5TCMBXGQZTMNJWUF3AE).
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
|
So how do I re-enable the disabled apps so that I can still get updates through homebrew, even if they aren't signed? Is there a solution here? |
You can consider hosting them in a personal tap, which is very easy to do: https://docs.brew.sh/How-to-Create-and-Maintain-a-Tap. You can use
brew extractto get the last version into your tap and then just let autobump make update PRs for you.