In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade sparkle-project/Sparkle
to version 2.6.1 or higher.
Affected versions of this package are vulnerable to Files or Directories Accessible to External Parties via the signing verification process, allowing an attacker to replace an existing signed update with another payload and bypass Sparkle’s (Ed)DSA signing checks.