the information about where a file was downloaded from, is stored in extended file attributes. it had nothing to do with code signature or md5 checksum. if necessary, you can clear it with cli
xattr -rc you can sign a built app from the cli or from 4D, but in addition to that, you need to sign the dmg or pkg if you want to distribute it over the network and pass gatekeeper. it is not possible to sign a zip. ********************************************************************** 4D Internet Users Group (4D iNUG) Archive: http://lists.4d.com/archives.html Options: https://lists.4d.com/mailman/options/4d_tech Unsub: mailto:4d_tech-unsubscr...@lists.4d.com **********************************************************************