MacCrabRave

Build Witness

com.maccrab.forensics.build-witness

Official v0.1.0 System Collector Content · encrypted scan
Install in MacCrab
Catalog minimum: MacCrab v1.22.3+

Publisher description

Current runtime: this plugin runs unsandboxed with MacCrab's access. Any sandbox wording in the publisher's signed description below reflects an earlier design. The access disclosure on this page describes the current execution path.

Compare selected artifact checkpoints from the same declared build run at built, signed and upload stages. Reports byte changes, filesystem-identity changes, newly observed files and files no longer observed. Incomplete observations produce inconclusive absence wording. Optional supplied MacCrab write exports add exact-path/time associations; a reported PID does not prove which process caused a hash change.

The installed collector is read-only and rejects --capture. The separate build-witness-tools companion explicitly captures a selected regular-file tree, recording SHA-256, size, device/inode and a capture interval. It uses bounded no-follow reads, detects observable changes during capture, and creates a new mode-0600 checkpoint outside the assessed tree without overwrite. Capture is not an atomic snapshot and never launches a build, signing command or upload.

Stage labels, run IDs, root paths and imported events are unauthenticated assertions. A signed label does not verify a signature, and upload does not prove uploaded bytes or destination. Legitimate signing can change bytes. Selected paths, digests, IDs, timestamps and counts require encrypted scans; file bodies, commands and environment values are withheld. Select checkpoints in MacCrab 1.22.3; missing, changed, malformed and over-limit evidence remains visible. First-party plugins inherit host access; manifest capabilities are declarations, not an independent OS sandbox.

What it reads

Publisher-declared sources for this catalog entry. This list describes intended collection; it does not confine an unsandboxed plugin's file access. The published app's install screen may show older static descriptions rather than the publisher declarations shown here.

  • checkpoint
  • write-events

Access and output privacy

Declared privacy requirements and the current execution path. Output classification describes what the plugin emits; it is separate from the files its process can read.

  • Declared macOS access No privacy services listed
  • Declared output Content data — requires an encrypted scan
  • Runtime Trusted, unsandboxed process. MacCrab validates its Developer ID signature before execution. It inherits the host's privileges, including available Full Disk Access.
  • Network The first-party execution path does not enforce an outbound-network block. A publisher's declaration of no network use is a behavior claim.

What it emits

Structured record types this plugin produces. Each row in your case database is one of these.

  • rave.collection
  • build_witness.finding
  • build_witness.summary

Discussion

Operator reports, caveats, and notes. Backed by GitHub Discussions on peterhanily/maccrab-rave-comments; sign in with GitHub to post.

Comments load from giscus.app — if you block third-party scripts, nothing appears here.

Discussion data is hosted by GitHub. The Giscus iframe loads from giscus.app. Operators with strict third-party-loader policies should skip this section.

Verification for v0.1.0

Release checks recorded on . These are the catalog's records for this version; this page does not perform a new independent build or collection test.

Source rebuild not applicable: this first-party entry does not publish a source repository for independent rebuilding. You can verify the publisher signature and pinned artifact digests against trusted keys. A recorded maintainer rebuild check does not provide independent source verification.

Recorded release checks
  • manifest-schema-v1
  • reproducible-build-verified
  • developer-id-signed
  • ed25519-signature-verified
  • publisher-key-pin-matched
  • publisher-key-not-revoked

Revocation status comes from the signature-verified revocation list (serial 2), issued . The website checks it during its build; MacCrab checks its own verified list when installing. The issue date does not describe the client's last successful fetch.

No revocation for v0.1.0 is recorded in that list.

Verify the signatures, artifact digests, and revocation list yourself.

Versions

Historical vetting is retained even when a release is revoked. “Current” identifies the version selected by the catalog.

VersionTagVettedRevocation statusReproducibilityCanonical hash
v0.1.0 currentv0.1.0No revocation recordedSource rebuild not applicableb7c2a84f53b872c1…