Updates
itokens keeps itself up to date, and installs only a release it can prove is genuine.
Checking
A released copy of itokens checks GitHub shortly after it opens and then once a day, while updates are switched on for itokens (the daily check-in says so; when they are off, itokens shows no update notice). Check any time in Settings (Check for updates, next to the version you have) or with itokens, Check for Updates in the menu bar. itokens asks GitHub at most every five minutes; a check sooner shows the last answer.
How an update is installed
A small updater does the work, in a window of its own, with a progress bar and each step as it happens: download the new version, check it (below), close itokens, install the new version, and open itokens again. itokens and its menu bar item close and come back by themselves; while itokens is still open, its window and menu bar panel say Update in progress with the same step. When a newer version is found as itokens opens, this starts by itself; it waits instead when something else is under way, such as a download, and then asks, as below.
The prompt
When a newer version comes out while itokens is running, itokens asks: Update Now, Later or Skip This Version, and shows that version's release notes in the same prompt, so you can read what changed before deciding. The orb in the menu bar gets a small dot, and the menu bar panel shows the new version with Update now.
What is checked before installing
- The download matches both GitHub's recorded checksum and the release's
SHA256SUMS. - The app inside is validly signed, by itokens's Developer ID team.
- Apple has notarized it (Gatekeeper accepts it).
- It is itokens, at exactly the version the release advertises.
If any check fails, nothing changes, and the updater says what went wrong with a button to open itokens. When all pass, itokens closes, the new version replaces the old one, and itokens opens again. The old copy is kept until the new version is running and put back if anything goes wrong. The updater's log is in ~/Library/Application Support/itokens/update.log.
Homebrew and source builds
If you installed with Homebrew, the updater runs brew upgrade --cask itokens in its window, showing Homebrew's progress, so Homebrew stays in charge; then itokens opens again.