Trust
Verify a download
hideouts apps are open source and built in public, but they aren’t notarized by Apple. These steps let you confirm that what you downloaded is exactly what was published, before you run it.
1. Download from the release page
Link to section: 1. Download from the release pageEvery download link on hideouts.io points to the project’s GitHub release page. Download the app archive and, when the release has one, its checksum file (SHA256SUMS.txt or .sha256) into the same folder. Don’t use copies from other sites or file-sharing services.
2. Check the SHA-256 checksum
Link to section: 2. Check the SHA-256 checksumA checksum proves the file wasn’t changed or corrupted after it was published. In Terminal, in the folder with the download:
shasum -a 256 NAME-OF-DOWNLOAD.zipCompare the result with the SHA-256 shown next to the download on the app’s page on this site, or on the GitHub release page. When the release includes a checksum file, let shasum compare the line for your download:
grep "NAME-OF-DOWNLOAD.zip" SHA256SUMS.txt | shasum -a 256 -c -The result must end in OK. If it says FAILED, or the digest is different, don’t open the file: delete it and download it again from the release page.
3. Verify the GitHub build attestation (where available)
Link to section: 3. Verify the GitHub build attestation (where available)Some releases are built by GitHub Actions and carry a signed build-provenance attestation. It proves the archive was produced by that repository’s own workflow, not uploaded from somewhere else. With the GitHub CLI installed:
For example, for iOS Developer Toolkit v0.3.4 on an Apple silicon Mac:
gh attestation verify iOS-Developer-Toolkit-v0.3.4-macOS-arm64.zip \
--repo hideouts-io/iOS-Developer-ToolkitUse the file name you downloaded and the repository it came from. The table on this page shows which releases have attestations. An attestation ties the file to the build; it doesn’t make an app notarized.
4. Check the code signature
Link to section: 4. Check the code signatureAfter unzipping and moving the app to Applications, check that the app bundle is intact:
codesign --verify --deep --strict --verbose=2 "/Applications/NAME.app"A pass means every file in the app still matches its signature. hideouts apps aren’t signed with an Apple Developer ID; most use an ad-hoc signature, which detects modification after signing but doesn’t identify a publisher. Each app’s signing status is listed on its page and in the table here. You can see the signature type with codesign -dv "/Applications/NAME.app"; an ad-hoc signature shows Signature=adhoc.
5. Open the app the first time
Link to section: 5. Open the app the first timeBecause the apps aren’t notarized, macOS may block the first launch even when every check above passes. That’s expected, and so is spctl --assess reporting rejected: it only means Apple hasn’t notarized the app. Use the per-app exception:
- Try to open the app once from Applications.
- If macOS blocks it, Control-click or right-click the app and choose Open, then Open again.
- On macOS 15 Sequoia and later, the dialog may only offer Done. Click it, open System Settings → Privacy & Security, and click Open Anyway next to the message about the app.
The exception applies to that one app. Never turn off Gatekeeper globally, disable System Integrity Protection, or remove quarantine attributes recursively. On a managed Mac, your administrator may need to approve the app.
If something doesn’t match
Link to section: If something doesn’t match- Delete the download and get it again from the GitHub release page.
- If a checksum, attestation, or signature check still fails, don’t run the app. Report it privately as described on the security page, with the file name, the digest you got, and where you downloaded it.
What the terms mean
Link to section: What the terms mean| Term | What it proves | What it doesn’t |
|---|---|---|
| SHA-256 checksum | The file is byte-for-byte what was published. | Who published it, if the release page itself were compromised. |
| Build attestation | The file was built by the repository’s own GitHub Actions workflow. | That the code is safe, or that Apple has checked it. |
| Ad-hoc signature | Files in the app haven’t changed since it was signed. | A publisher identity. Anyone can ad-hoc sign. |
| Developer ID + notarization | Apple has identified the developer and scanned the app. hideouts apps don’t have this yet. | That the app is free of bugs or vulnerabilities. |