Alcatraz – Package manager for Xcode 5
alcatraz.io
alcatraz.io
While the download itself is served using https (from amazon), curl will contact the google url shortener using HTTP. Honestly, if I wanted to MITM one thing on any network, URL shorteners would come first.
Edit: The website switched from googles link shortener to git.io (http) and download to github downloads. git.io's https version seems to have certificate issues.
> curl https://git.io/lOQWeA -vvv
...
* SSL certificate problem: Invalid certificate chain
...Whoever wrote the installation instructions here should take a page from Sublime Package Control's installation instructions:
> The download will be done over HTTP instead of HTTPS due to Python standard library limitations, however the file will be validated using SHA-256.
> WARNING: Please do not redistribute the install code via another website. [Because of the embedded SHA-256 digest, the installation code] will change with every release. Instead, please link to this page.
Also, git.io allows only shortening github repos; so there should be no harm
Really?
Who do you think your target audience is? I'm sorry, but this is not "really long":
https://github.com/supermarin/Alcatraz/releases/download/1.0.1/Alcatraz.tar.gz
If you're telling people to run random commands in their terminal that lead to local code execution, then you should trust that they can read a goddamn URL.If you don't think your user base can read URLs, then you shouldn't be telling them to launch the terminal and run your code.
It doesn't matter if git.io can only shorten git urls, as git.io will never be involved in a potential attack.
Using a link shortener is okay, but use one that supports HTTPS.
Given that it's for Xcode, the one dev-tool to rule them all, in the walled garden where Apple has all the keys, I think it fits perfectly.
There are Ruby "Gems" and Cocoa "Pods", I'm trying to think of a similar name that evokes something that can be slotted in to something else... Cubby?
Cubby - any of a group of small boxlike enclosures or compartments, open at the front, in which children can keep their belongings, as at a nursery school.
An aside: Has anyone tried the Clang Formatter plugin? I want to format property declarations like:
@property (nonatomic, strong) NSString *string;
But setting 'ObjCSpaceAfterProperty' to true or false both output: @property(nonatomic, strong) NSString *string;
My format config is based off llvm's. Maybe some other configuration is stomping on the 'ObjCSpaceAfterProperty: true'?(Does anyone have a .clang-format file that that matches Apple's style?)
I should note that Alcatraz's clang plugin looks to have a compiled version of an old clang-format in the tree...that's likely why this doesn't work with that plugin.
Thanks for adding that ObjC option.
It allows you to generate a doc string for a method if you type '///'
I'm super excited to see it out and one-click installable again. Looking forwards to seeing what Marin/Delisa/Jurre do with the blog.
I use this regularly, it's not felt any less stable for the few plugins I use mainly; open in github, one in appcode & fuzzy string matcher. They really make Xcode easier for day to day life.
If you do have issues with a particular package it is pretty simple to remove any/all of them. The only time I have had issues is when I've tried to run betas of Xvim on unreleased versions of Xcode.
Seriously, if you're interested at all in the packages made available through Alcatraz give it a shot.
If the tools solve useful problems, who cares if they break later? We'll fix them.
I would very strongly caution against Apple continuing to provide such a boneheaded IDE.
The existence of the compatibility UUID does not mean that Apple has blessed plugins. They're just trying to reduce their support load, and reduce their users' crashes at the same time.
Are you planning to have a forum somewhere for feedback and support? I suppose I could open an issue on Github, but I'd really rather just ask a question. Enough people seem to be using this that I suspect the problem is on my end.
Theoretically speaking, is it safe to curl and install something via plain http:// and no checksum verification?
Congrats on the launch Marin! Been following the repo for a few months now, I'm really digging the design.
The few I've tried haven't been great (they've tended to crash a lot and break with Xcode updates)
A bit of work was required when Xcode 5 came along but from minor version to minor version they haven't needed much in the way of maintenance.
I work for TheMan® (with Firewall) and assuming it is due to some non-http ports being used?
#EnterpriseLife
As to the security review or process, perhaps badging -- that sounds like a good feature request. I'll bet there's an issue tracker... ;-)
At last!