Updates and verification

Understand how VibePapers checks for releases and how to verify an unsigned download.

Signed update information

Update manifests are delivered over HTTPS and signed with Ed25519. VibePapers rejects update information that cannot be verified with its embedded public key.

No silent installation

Automatic checks run at most once per day. When an update is available, VibePapers opens the official download page; it never downloads or installs an update by itself.

Verify the DMG

Compare the SHA-256 value of the downloaded DMG with the checksum published on the Download page. A mismatch means the file must not be opened.

Unsigned public beta

Current public beta builds are ad-hoc signed, not Developer ID signed, and not notarized. Download them only from the official VibePapers website.