Homebrew: Locking Down the macOS Sandbox

Homebrew tightened its macOS sandbox policy across two pull requests while also hardening cask linting to catch bad checksum patterns and dangerous uninstall rules, continuing a broader push toward safer defaults for both infrastructure and formula authors.

Duration: PT2M28S

Episode overview

This episode is a short developer briefing from Homebrew.

It explains recent repository work in plain language.

  • Show: Homebrew
  • Published: 2026-09-10T13:17:46Z
  • Audio duration: PT2M28S

Transcript excerpt

This excerpt keeps the crawler page concise. Listen to the episode or use the RSS feed for the full update.

Good morning. It's September 10th, and today's Homebrew activity centers on one theme: tightening the security perimeter, both in the sandbox and in cask linting.

Mike McQuaid landed two related changes to the macOS sandbox. PR 23909 disables application launching and cross-app automation for sandboxed subprocesses, even when network access is on, keeping sandboxed work strictly command-line. A follow-up, PR 23920, still open, restores some legitimate functionality that got…

On the cask side, linting got smarter. P-linnane's PR 23901 teaches the cask cop to hoist duplicate SHA-256 checksums out of paired macOS and Linux blocks into a single stanza, but it's deliberately conservative — it declines to autocorrect when the result could be wrong. Bevan Kay's PR 23908 adds a rejection rule…

A few other items worth flagging. Bevan Kay also fixed a caching bug in the curl download strategy, PR 23917, where a redirect's content type was blocking legitimate last-modified and content-length checks. And on infrastructure, PR 23918 adds bottle transition tracking so formulae don't silently lose Apple Silicon…

Two cask artifact PRs for Linux native packages, 23911 and 23912, are open from…

What's…

Nearby episodes from Homebrew

  1. Locking Down the Sandbox
  2. Closing the Extension Point Gaps
  3. Trust, Security, and the Advisory History Cleanup
  4. Weekly Recap - Hardening the Trust Chain
  5. A Sandbox Hardening Sprint
  6. Raising the Floor, Closing the Gaps
  7. Cask Security Hardening and the Master Branch Freeze
  8. Tightening the Seams on Services and Security