Reporting a vulnerability
If you find a security problem, please report it privately first rather than opening a public issue. Use GitHub's private vulnerability reporting on the repository.
Please include what you found, the version you tested, and the steps to reproduce it. Once a fix ships, the advisory is published with credit unless you would rather not be named.
Supported versions
Overhang is a small utility with a single active line. Fixes are issued for the latest release only.
| 0.5.x | Supported |
|---|---|
| Earlier | Not supported, please update |
Code signing and distribution
Where to get it
The only official builds are the releases published on the project's GitHub repository. Copies obtained anywhere else should be treated as untrusted.
Signature
Release builds are signed with an Apple Developer ID certificate, and you can verify a download before running it:
codesign -dv --verbose=2 /Applications/Overhang.app
Notarization
Release builds are notarized by Apple and the ticket is stapled to the disk image and to the app, so the app launches normally and validates even with no network connection. You should never need to disable Gatekeeper or right click to open it. If a build asks you to, it did not come from this project.
You can confirm the ticket on your own copy:
spctl -a -vvv -t install /Applications/Overhang.app xcrun stapler validate /Applications/Overhang.app
The first command should report:
accepted source=Notarized Developer ID
Permissions and what they allow
Accessibility, optional
Overhang uses it for exactly one operation: pressing a status item that you chose from its menu. It does not register event taps, does not observe keystrokes, and does not read the contents of other applications. The relevant code is a single function in Sources/Activator.swift and is short enough to read in full.
Dependencies
Overhang has no third party dependencies. It links only Apple system frameworks and nothing can be pulled in at build time from an external registry.
Hardened runtime and sandbox
The app is not sandboxed. Reading the position of other applications' menu bar items, and optionally pressing them, is not expressible inside the App Sandbox, so sandboxing it would remove the feature entirely.
This is a real trade off and is stated here rather than omitted. The mitigation is that the entire source is published, the binary has no network access, and the app requests no permission unless you turn on click through.
Verifying a build yourself
Because the source is public and there are no dependencies, you can build the app from source and compare behaviour rather than trusting the published binary.
git clone https://github.com/nicglazkov/overhang.git cd overhang make test make install