Changelog

Progress without turning builds into releases.

Every entry carries a date and status. “Release candidate” and “Internal validation build” do not mean a public, signed, notarized download; only the exact version backed by the qualified release manifest is shown as public.

0.4.0

PinShift Pro adds secure, installation-bound licensing while preserving the local-first location workflow.

  • Adds PinShift Pro plans, signed installation-bound entitlements, and secure restore, refresh, and deactivation flows.
  • Stores reusable billing recovery credentials in the native macOS Keychain and migrates legacy local credentials safely.
  • Keeps Restore Real Location available on every plan and strengthens activation and device-limit safety.
  • Fixes Live billing CSP coverage, same-Mac reactivation, native refresh persistence, and native customer portal access.

0.2.15

A universal Mac candidate that corrects clean-install process discovery without weakening its launch, identity, or stability checks.

  • Discovers the LaunchServices-started app by its exact bundled Mach-O path rather than a display process name.
  • Retains quarantined DMG assessment, Developer ID validation, notarization, stapling, Gatekeeper, architecture checks, and owned-PID cleanup.
  • Uses the one-time named first-public-release updater exception; all later releases require an update test from the preceding public version.
  • Remains unavailable until the protected release workflow completes every qualification gate.

0.2.14

An unpublished protected universal Mac candidate that passed signing, notarization, and Gatekeeper but stopped at clean-install process discovery.

  • Rotates the unpublished updater signing key so the embedded public key verifies future signed archives.
  • Uses the canonical pinshift.pages.dev origin for immutable downloads and updater metadata.
  • Stopped before publication because the clean-install process discovery relied on a LaunchServices display name instead of the exact executable path.

0.2.13

A bounded clean-install qualification candidate for the first public universal Mac release.

  • Bounds the installed-app launch before the exact process and stability checks on both Mac architectures.
  • Keeps the universal Developer ID, app and exact-DMG notarization, stapling, and Gatekeeper gates intact.
  • Was superseded as the updater bootstrap candidate after it did not qualify or publish.

0.2.12

An unpublished candidate that passed signing and notarization but was cancelled during clean-install qualification.

  • Signs the exact universal DMG with Developer ID before submitting those same bytes to Apple notarization.
  • Requires Apple's Accepted result, staples the DMG ticket, and validates Gatekeeper before the candidate can be sealed or uploaded.
  • Stopped before clean-install evidence or publication when the installed-app launch blocked both qualification jobs.

0.2.11

An unpublished attempt that passed app security checks but stopped because the DMG had no stapled ticket.

  • Reworked the public site around everyday use cases, realistic privacy-safe screenshots, responsive layouts, and one canonical home.
  • Added a private R2 download gateway with strict release-path allowlisting, resumable downloads, and fail-closed public manifests.
  • Added release credential preflight and immutable approval attestation bound to the exact signed candidate.
  • Fixed updater installation state and stabilized concurrent worker-supervisor verification.
  • Fixed protected release lint so generated universal Python dependency trees are excluded and the rule is regression-tested.
  • Built a universal Developer ID-signed, notarized, stapled app accepted by Gatekeeper, then stopped before candidate upload when the DMG ticket check failed.

0.2.10

An unpublished release attempt that stopped during validation before signing or packaging.

  • Added a user-focused Help Center, troubleshooting paths, updater documentation, and practical location-testing guides.
  • Added reproducible privacy-safe product screenshots, responsive examples, and an optimized social sharing image.
  • Added a fail-closed universal release manifest so an unqualified DMG cannot become a public download by accident.
  • Documented signed in-app updates, immutable Cloudflare R2 artifacts, release checks, Search Console setup, and rollback.

0.2.3

Local Apple Silicon packaging and end-to-end product validation milestone.

  • Validated the frontend, Rust layer, Python bridge, demo capture, and a local Apple Silicon bundle.
  • Documented that the development artifact used ad-hoc signing and was not eligible for public distribution.
  • Kept public availability blocked pending Developer ID signing, hardened runtime, notarization, and release review.

Subscribe to the changelog RSS