List of vulnerable applications is here - https://github.com/sparkle-project/Sparkle/issues/717
I would consider it as 2 different vulnerabilities.
Things like this is why The Update Framework (TUF) Specification was created:
https://theupdateframework.github.io/
The specification covers exactly this kind of attack and has signing of all of the data about an update:
https://github.com/theupdateframework/tuf/blob/develop/docs/...
But, as far as I know, there isn't an implementation of TUF that works with ObjectiveC and all the other parts of Sparkle, to actually update an OSX application.