An app that watches your cloud credentials should be able to say precisely what it can touch.
This is the design decision the rest of the trust model rests on.
GCloud Dot does not read, copy, cache, or transmit tokens. It asks gcloud
a question, auth print-access-token, and looks only at whether
the command succeeded and, if not, at which error it printed. The token
itself is discarded without ever being examined.
It follows that a compromise of this app grants no credential it did not already have. Anything able to run it could have run gcloud directly.
No permission covers any of that on any platform, which is why the app never asks for one. It is not sandboxed and does not claim to be.
The panel is rendered in the system webview from a string of HTML built inside the app. It loads no remote content, has no network access it could use, and executes no script that did not ship in the binary.
Every value that reaches it from outside, your account address, project id, and configuration name, is HTML-escaped before it is inserted, and there is a test that fails if that stops being true. A configuration name is arbitrary text a user typed, so it is treated as hostile.
Signed with a Developer ID certificate, hardened runtime enabled, and notarized by Apple. The app is notarized and stapled before the disk image is built, and the disk image is then notarized and stapled itself.
That second step is the one most often skipped, and the one worth insisting on. Notarizing only the DMG leaves the app inside it without a ticket. Gatekeeper covers for that by asking Apple online, so the gap is invisible on a connected machine and blocks the person whose first launch is offline, on a plane, or behind a captive portal, which is exactly when someone reaches for a tool about expired credentials.
To check for yourself:
spctl -a -vvv -t install "/Applications/GCloud Dot.app"
xcrun stapler validate "/Applications/GCloud Dot.app"
Not code-signed yet, so SmartScreen warns on first run. Stated plainly rather than buried: a certificate is a recurring cost this project has not taken on. Verify the checksum instead.
Each release carries SHA256SUMS.txt, generated by the same
workflow run that built the binaries. Every artifact is built in public by
GitHub Actions from a tagged commit, and the whole build is readable in
.github/workflows/release.yml.
Deliberately few. The engine uses only serialisation and date handling.
The tray adds the icon, menu, webview, and notification libraries it cannot
reasonably reimplement. There is no HTTP client and no TLS stack: the update
check shells out to curl, which every supported system already
ships, rather than linking a dependency tree larger than the rest of the app
for one request a day.
Email nic@glazkov.com, or open a private advisory on GitHub. Please do not open a public issue for a vulnerability until it is fixed.
This page describes GCloud Dot 1.1.11.