Sparkle: A software update framework for macOS
github.com
github.com
The days when I’d mostly use downloadable native software for my Mac.
The days when most of the software I regularly used had a somewhat consistent UX.
You could start here, if you are interested, to get a taste: https://matrix.org/docs/chat_basics/matrix-for-im/#creating-...
Granted, I don't expect Pidgin plugins to be well maintained compared to the Matrix appservice bridges. But still, there is at least one protocol that bridges to almost everything, and that's Matrix. For several years I used Matrix as little more than a glorified IRC and Slack client.
I think there is a certain type of company that go for fairly generic(named) software with a lot of SEO and marketing to be able to earn a lot of money. I guess there is a venn diagram of malware creators where this applies too but I don't think they are.
They are also the developers behind SetApp. I mean, that's a pretty mainstream/famous app(store?) so they collaborate directly with loads of developers/companies to distribute their apps in SetApp. If that counts for something.
DND is not properly/reliably detectable for 3rd parties. Support for Notification Center is not well designed for a framework to control and works as an auxiliary/supplemental (not primary) functionality for 3rd parties, so apps themselves would have to opt into using it along with adding a lightweight UI indicator which may need to be tailored to the app in question.
Further support is available for apps to support more gentle reminders -- https://sparkle-project.org/documentation/gentle-reminders/ which is a mechanism that iTerm developer wanted but developer has other priorities.
Users can opt into automatically downloading/installing updates too which may minimize prompts
The new version with delta updates and flags for critical updates is amazing. 10/10
brew update; brew upgrade; brew cleanup; brew doctor buucbrew update && brew upgrade && brew cleanup && brew autoremove
I'd hazard a guess that Chrome alone would put that figure near 100%
The whole malicious compliance shebang. EU mandates browser choice, so Apple implements new technological measures to ensure that browser choice will still not be offered outside the EU
Edit: Obviously for users not familiar with command line programs brew isn't that "easy". But for command line people this setup is quite nice.
Great piece of software.
Big kudos to all contributors of Sparkle, you all make our lives easier!
Also I worry about update frameworks as way for bad guys to do bad things via my software. Should I be worried?
In general, I wouldn't worry too much about Sparkle being a vulnerability. It requires that your download servers are hacked: https://9to5mac.com/2017/05/08/handbrake-trojan-mac-malware-...
Presumably Sparkle and Winsparkle both use a similar update mechanism and that doesn't involve full Windows or Mac installers (otherwise, what would be the point?).
I can't speak much for Winsparkle; I remember looking at it and immediately concluding that it wouldn't work for us.
(FWIW: I ended up slipping in a few hacks so we could pop open browser windows on specific versions and commits, and even remotely kill them if needed.)
For C++, WinSparkle works too: https://github.com/vslavik/winsparkle/
That being said, I think the way sparkle (and winsparkle, see sibling) present themselves looks delightfully NSIS (the good parts)
I am constantly amazed and frustrated at how many apps I use on Windows have the following update process:
1. Pops up an alert telling me an update is available
2. I click a link in the alert opening my browser, taking me to a webpage full of links for different OSes and different architectures, which I have to search through to find Windows Intel x64
3. Wait to download the new version and then open it up
4. Spend 30 seconds clicking through a Windows Installer
Absolutely bonkers, especially considering some of these apps seem to release on an agile biweekly schedule. I usually procrastinate downloading updates because it's such a pain in the ass -- and that's not what you want your users to be doing.
Now I know it exists - thanks!
[1]: https://github.com/Squirrel/Squirrel.Windows/tree/develop/do...
[2]: https://github.com/electron/electron/blob/main/docs/api/auto...
https://learn.microsoft.com/en-us/windows/msix/non-store-dev...
Or just publish to MS Store and/or winget.
In terms of proper package management a la yum or apt, there is homebrew of course.
Doesn't that leads to the situation on windows where every single app is phoning home at startup?
> Doesn't that leads to the situation on windows where every single app is phoning home at startup?
Sparkle has a very clear and regular behaviour, its predictability and widespread use made it easy to manage.
1) It's a setting/preference. The polite/respectful app developers will ask users whether they want to automatically check for updates.
2) It's periodic. Developers can set the default to whatever they prefer — daily, weekly, monthly, etc. — and again the polite developers may give the user an option here too.
I mean you can have an option to not make it check for updates if you want to provide a privacy option for people, but that just makes it a manual click-to-check-for-updates. Most people would probably leave the "check for updates on start" checked.
Can't see how that's a difference based on what OS you are on? I use Squirrel/Velopack (the equivalent for Windows I guess) and the usual way of managing updates is to have an update check at startup, or an interval (e.g. every hour).
I have been a linux and openbsd user for the most part of the last 3 decades with only short stints on windows in a professionnal setting or when fixing up my partner's issues and nearly 0 experience of macOS apart from launching it in a VM out of curiosity 3 times so I was genuinely surprised and not aware of potential restrictions of app store. I know on windows there is the microsoft store + chocolatey that can handle apps updates (and possibly other projects?).
I have had the occasionnal java app installed in /opt from a tarball or an appimage but for me apps individually phoning home is more the exception than the norm. I usually have one process connecting to n repos, n being less than 5 usually and usually only when I am querying it manually. In recent years on Fedora I've let gnome software app connecring automatically and I guess with some flatpaks installed I am querying 2 flatpak repos (fedora +flathub) more but that's about it and most of our distro packages have telemetry and users counts disabled.
Interesting things could happen with third party App Stores if they ever see the light in macOS.
In that case I understand that Setapp can "phone home" and update the apps if necessary, not the apps themselves.
MacPorts keeps things clean in /opt/.
https://saagarjha.com/blog/2019/04/26/thoughts-on-macos-pack...
Wanted to give it another shot with my latest clean OS install, but wound up installing Homebrew again due to broken packages on MacPorts. Probably should’ve tried to contribute by fixing those packages but didn’t have the time or mental energy available at that point in time.
Installation is similar just a standard mac install. apps are the same.
The only difference is that Homebrew gets confused if you install your code or another build in /usr/local oh and Homebrew forces you to use non standard permissions on /usr/local
Homebrew was less hassle in that most of the time, it successfully installed things and when it didn’t, it was fixed in short order.
Since then I’ve become much more capable of diagnosing and fixing broken packages but it’s still not something I’d like to spend my time on if I can help it.
I install pretty much everything I need on macOS through Homebrew these days.
I guess the Microsoft Office suite, LibreOffice, Adobe Lightroom, Pixelmator, Sketch, OmniGraffle, etc. are trivial?