That's the reason Apple added this signing feature. I'm just wondering if there's really a good reason for a developer to not follow it.
That doesn't make it better. What if your internet connection craps out while it's downloading the line "rm -rf /usr/local/bin/old-binary" and it happens to stop at "rm -rf /usr"?
Oops.
https://github.com/brunophilipe/Cakebrew/releases/tag/v1.0.2
Again, nobody has answered what the problem is with signing the installer. What gives?
The point of the killswitch is to disable malicious software that someone tricked you into downloading off the internet and installing. That is the only thing it would be used for (and I'm not aware if it ever has.. maybe because it's a good deterrent).
It is not the same as the broader App Store approval guidelines. This is specifically for disabling malware, e.g. a bad actor tricking 10% of Hacker News into installing a malicious fork of brew.
I also want to make it clear I have no reason to believe this developer is anything but trustworthy. I just am curious why they decided not to sign it.
I'd gladly fork it and replace it with a signed binary, but I'd want to ensure there isn't anything suspect in the project.
And seriously, I've never even heard of the kill switch being used for anything that wasn't malicious. Especially if it's not distorted in the Mac App Store.