GCloud Dot
← GCloud Dot

Security

An app that watches your cloud credentials should be able to say precisely what it can touch.

It never handles your credentials

This is the design decision the rest of the trust model rests on.

GCloud Dot does not read, copy, cache, or transmit tokens. It asks gcloud a question, auth print-access-token, and looks only at whether the command succeeded and, if not, at which error it printed. The token itself is discarded without ever being examined.

It follows that a compromise of this app grants no credential it did not already have. Anything able to run it could have run gcloud directly.

What it can reach

No permission covers any of that on any platform, which is why the app never asks for one. It is not sandboxed and does not claim to be.

The details window

The panel is rendered in the system webview from a string of HTML built inside the app. It loads no remote content, has no network access it could use, and executes no script that did not ship in the binary.

Every value that reaches it from outside, your account address, project id, and configuration name, is HTML-escaped before it is inserted, and there is a test that fails if that stops being true. A configuration name is arbitrary text a user typed, so it is treated as hostile.

Releases

macOS

Signed with a Developer ID certificate, hardened runtime enabled, and notarized by Apple. The app is notarized and stapled before the disk image is built, and the disk image is then notarized and stapled itself.

That second step is the one most often skipped, and the one worth insisting on. Notarizing only the DMG leaves the app inside it without a ticket. Gatekeeper covers for that by asking Apple online, so the gap is invisible on a connected machine and blocks the person whose first launch is offline, on a plane, or behind a captive portal, which is exactly when someone reaches for a tool about expired credentials.

To check for yourself:

spctl -a -vvv -t install "/Applications/GCloud Dot.app"
xcrun stapler validate "/Applications/GCloud Dot.app"

Windows

Not code-signed yet, so SmartScreen warns on first run. Stated plainly rather than buried: a certificate is a recurring cost this project has not taken on. Verify the checksum instead.

Every platform

Each release carries SHA256SUMS.txt, generated by the same workflow run that built the binaries. Every artifact is built in public by GitHub Actions from a tagged commit, and the whole build is readable in .github/workflows/release.yml.

Dependencies

Deliberately few. The engine uses only serialisation and date handling. The tray adds the icon, menu, webview, and notification libraries it cannot reasonably reimplement. There is no HTTP client and no TLS stack: the update check shells out to curl, which every supported system already ships, rather than linking a dependency tree larger than the rest of the app for one request a day.

Reporting something

Email nic@glazkov.com, or open a private advisory on GitHub. Please do not open a public issue for a vulnerability until it is fixed.

This page describes GCloud Dot 1.1.11.