Am 02.01.2026 um 10:45 schrieb Pavel Sanda <[email protected]>: > > On Tue, Dec 09, 2025 at 05:37:21PM +0900, Koji Yokota wrote: >> I tried to run macOS LyX binary (version 2.4.4) but macOS Gatekeeper >> prevents to do so, saying that it cannot check if malware is included in the >> app. >> >> Homebrew, a major app manager, says: >>> Warning: lyx has been deprecated because it does not pass the macOS >>> Gatekeeper check! It will be disabled on 2026-09-01. >> >> I???m not sure from when this problem exists, but probably after the version >> update of macOS. Can this be amended? > > I hope the only thing which changed is homebrew decision not to support > unsigned casks. > Koji, can you try the usual trick to bypass gatekeeper when downloading .dmg > directly from lyx ftp site? > > There are myriads of articles on the web how to bypass gatekeeper, including > completely disabling it, eg: > https://nordvpn.com/blog/macos-cannot-verify-this-app-is-free-from-malware/ > > Pavel > > PS: I personally think that from both a) philosophical and b) practical > reasons I don't think we should officially support apple signing. > > a) It's absurd to pay apple so we can improve it's ecosystem by our own free > work. > They have fee waiver for non-profits, but unless someone wants to lead us > through the legalization to become formal organization, that's no-go. > (I did not check, but there might be some umbrella org for signing > established floss projects?) > > b) Unless Stephan is inclined to pay from his own pocket or accept donations > any lyx-money related operations are pain when you start considering > tax-related issues. > (Stephan do you have some opinion about this?) > > I read that homebrew supports unofficial taps, where signatures are not > required, so someone might try to establish this for lyx as well later…
The DMG from LyX ftp-site is signed with a self-created key. I made this key. There was a discussion about this topic in 2013 mails with the subject „LyX.app can't be opened“ … I can afford the fee - but… That time (2013) I had a problem with signing a „contract“ I cannot 100% understand. And I see the ethical problems about FOSS and (recurring!) payments for a license to distribute it. Of course I’m interested in a safe software infrastructure too. I accept that Apple has a responsibility to that and has to provide a way to distribute software as securly as it can. The best option would be to have the option to sign the software w/o fee somehow. I’d prefer to get a key as an official organization. Perhaps TUG got it w/o fee? Stephan PS: Sorry for being late - I’m really busy… -- lyx-devel mailing list [email protected] https://lists.lyx.org/mailman/listinfo/lyx-devel
