github Oct4Pie/archify v1.5.0

3 hours ago

Security

  • Every change to an app in /Applications now requires administrator approval, which the helper verifies before acting.
  • The helper accepts connections only from Archify signed by the same developer. On macOS 12 the check uses the connecting process's audit token instead of its process ID.
  • The helper can only optimize apps and remove language folders. Its older file operations that accepted any path are gone.
  • Helper paths are checked without following symbolic links, and requests outside the app being changed are refused.
  • The helper prepares changes in a folder only the system can modify and reads app files without following links, so other programs cannot redirect what it writes.
  • The helper only reads ordinary files, so a file swapped for a special one cannot stall it.
  • The helper exits when idle, so no root process lingers and an updated helper is used from the next operation.
  • The Archify 1.4 helper is replaced automatically, with no restart or logout.

Safer optimization

  • Optimization is transactional: each app is changed with an atomic swap and rolled back on any failure. If macOS blocks a change, nothing is changed.
  • Thinned binaries are stored with macOS transparent compression (LZFSE). They read back byte-for-byte unchanged, so signatures stay valid, and they take far less disk space. Previously, apps that macOS had already compressed could use more space after optimizing.
  • Sizes and savings now show actual space on disk.
  • Files sealed by an app's signature are left alone, so optimized apps keep a valid signature and stay notarized.
  • Open apps are detected before changes. Archify offers to quit them, or skips them.
  • Optimize Apps, Languages, scans and size calculations can be paused, resumed or canceled.
  • Optimize App never overwrites an existing app. It offers Keep Both or Replace (which moves the old copy to the Trash). The copy is made in a private folder and moved into place only if nothing has appeared there in the meantime. Destination folders that other users can change are refused.

Permissions

  • Full Disk Access is no longer required at launch. It is requested only when macOS protects an app from changes, with step-by-step guidance and a direct link to the setting. This fixes repeated Full Disk Access prompts on some Macs (#15).
  • Helper approval opens Login Items and continues on its own once you approve it. On macOS 13 and later the helper is listed under Archify's name (#13).

Languages

  • A redesigned Languages screen: pick languages, review the affected apps, and see how much space each choice frees.
  • Your preferred languages and each app's development language are always kept. Language folders that an app's signature requires are never removed.
  • If a language folder can only be partly removed, Archify says so instead of reporting that nothing changed.

Apps and architectures

  • A redesigned interface with Optimize App, Optimize Apps, Space Savings, Languages and Installed Apps.
  • More accurate architecture detection, including apps with nonstandard layouts, arm64e and x86_64h (#12).
  • Detects the real Mac architecture when running under Rosetta.
  • Faster scanning.
  • Universal build for Apple Silicon and Intel, macOS 12 or later.
  • Remembers the window's size and position.

Updates

  • Automatic updates through Sparkle, with signed archives and a signed update feed (#14). Updating from 1.4 requires one manual install of 1.5.

Command-line tool

  • Transactional optimization that keeps sealed files, the same as the app.
  • Never overwrites an existing app at the destination, even one that appears while copying, and refuses output folders that other users can change.
  • Refuses to run as root or with sudo, which it never needs, and never writes its log through a link.
  • Thinned binaries are stored compressed, the same as the app. Use --no_compress to turn this off.
  • Apps without entitlements are no longer reported as signing failures.

Removed

  • The bundled LDID source. LDID signing now uses an ldid you install, for example with brew install ldid.

Install

Download Archify-1.5.0.zip, unzip it, and move Archify to /Applications. Archify 1.4 users need to install 1.5 by hand once; later updates arrive automatically.

SHA-256 of Archify-1.5.0.zip: cf61cc9ac7cc7080dd13f9e879d009dd3b019c603da3df886250f63e00eb8f14

Don't miss a new archify release

NewReleases is sending notifications on new releases.