Files
brov-macbook/NotchBuddy/project.yml
T
maksarsanjeev 52e1e8288b Security + upstream fixes
- Network core moves to a root-only folder; BroV talks to a narrow root helper (netctl.py) over a user-only socket; install script verifies the mihomo SHA256 and migrates keys (scripts/netcore)
- Hardened runtime, no get-task-allow; bypassPermissions removed from the chat; concealed clipboard items are not restored; DangerCheck knows core, LaunchAgents and hook paths; dropped-file copies expire after 7 days
- Ported from upstream Coucou: 1h crash fix (d05f22b), safe settings.json writes (918d30e), Escape/fold for pending approvals (6012900, 40e3ba8), auto-close delay + reopen (74984f2, ea244a7), full AskUserQuestion (52b1562)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-07 23:49:11 +03:00

88 lines
2.5 KiB
YAML

name: BroV
options:
bundleIdPrefix: local.maksar
deploymentTarget:
macOS: "15.0"
xcodeVersion: "27.0"
createIntermediateGroups: true
# BroV — personal fork of Coucou (MIT). Mac app only, local unsigned builds.
configs:
Debug: debug
Release: release
settings:
base:
SWIFT_VERSION: "6.0"
# Hardened runtime, no get-task-allow: other processes can't inject code into BroV
# and borrow its Accessibility / Apple Events permissions.
ENABLE_HARDENED_RUNTIME: YES
CODE_SIGN_INJECT_BASE_ENTITLEMENTS: NO
CODE_SIGN_ENTITLEMENTS: Resources/BroV.entitlements
OTHER_SWIFT_FLAGS: "-strict-concurrency=complete"
# Ad-hoc signature: runs locally, no Apple Developer account needed.
CODE_SIGN_STYLE: Manual
CODE_SIGN_IDENTITY: "-"
CODE_SIGNING_REQUIRED: NO
CODE_SIGNING_ALLOWED: YES
DEVELOPMENT_TEAM: ""
# The only third-party dependency: a real terminal emulator for the term.macOS tabs.
packages:
SwiftTerm:
url: https://github.com/migueldeicaza/SwiftTerm
from: 1.20.0
schemes:
BroV:
build:
targets:
BroV: all
run:
config: Debug
archive:
config: Release
targets:
BroV:
type: application
platform: macOS
sources:
- path: Sources
type: group
- path: Assets.xcassets
buildPhase: resources
- path: Resources/sounds
buildPhase: resources
type: folder
- path: Resources/memoji
buildPhase: resources
type: folder
dependencies:
- package: SwiftTerm
info:
path: Resources/Info.plist
properties:
CFBundleName: BroV
CFBundleDisplayName: BroV
CFBundleIdentifier: local.maksar.BroV
CFBundleVersion: "1"
CFBundleShortVersionString: "0.1.0"
CFBundlePackageType: APPL
LSUIElement: YES
NSHighResolutionCapable: YES
NSSupportsAutomaticGraphicsSwitching: YES
NSAppleEventsUsageDescription: "BroV jumps to your terminal, sends mail and controls Music."
NSAccessibilityUsageDescription: "BroV reads the front window's title to attach it as context."
NSAppTransportSecurity:
NSAllowsLocalNetworking: true
settings:
base:
PRODUCT_BUNDLE_IDENTIFIER: local.maksar.BroV
PRODUCT_NAME: BroV
PRODUCT_MODULE_NAME: NotchBuddy
INFOPLIST_FILE: Resources/Info.plist
ASSETCATALOG_COMPILER_APPICON_NAME: AppIcon
MACOSX_DEPLOYMENT_TARGET: "15.0"
ENABLE_SANDBOX: NO