#!/bin/sh # SilkNest installer: downloads the app from silknest.app, checks its SHA-256 and code signature, # and installs it into Applications. Nothing else on your Mac is touched. set -eu VERSION="1.0.0" URL="https://silknest.app/SilkNest-${VERSION}.zip" SHA256="9cf159b0a247c3b5cf2c2f857c0f0331d89c400ca8987b3b4e416715f5006157" say() { printf '\033[38;5;214m●\033[0m %s\n' "$1"; } fail() { printf '\033[31m✕\033[0m %s\n' "$1" >&2; exit 1; } [ "$(uname -s)" = "Darwin" ] || fail "SilkNest is a Mac app." [ "$(uname -m)" = "arm64" ] || fail "SilkNest ${VERSION} needs a Mac with Apple Silicon." major=$(sw_vers -productVersion | cut -d. -f1) [ "$major" -ge 14 ] || fail "SilkNest needs macOS 14 Sonoma or later." tmp=$(mktemp -d) trap 'rm -rf "$tmp"' EXIT INT TERM say "Downloading SilkNest ${VERSION}…" curl -fsSL --proto '=https' --tlsv1.2 "$URL" -o "$tmp/SilkNest.zip" || fail "Download failed. Check your connection and try again." echo "$SHA256 $tmp/SilkNest.zip" | shasum -a 256 -c - >/dev/null 2>&1 || fail "Checksum mismatch: the download was not the file published on silknest.app. Nothing was installed." ditto -x -k "$tmp/SilkNest.zip" "$tmp" || fail "Could not unpack the download." codesign --verify --deep --strict "$tmp/SilkNest.app" 2>/dev/null || fail "The app's signature is not intact. Nothing was installed." dest="${SILKNEST_DEST:-/Applications}" [ -w "$dest" ] || { dest="$HOME/Applications"; mkdir -p "$dest"; } pkill -x SilkNest 2>/dev/null && sleep 1 || true rm -rf "$dest/SilkNest.app" ditto "$tmp/SilkNest.app" "$dest/SilkNest.app" xattr -dr com.apple.quarantine "$dest/SilkNest.app" 2>/dev/null || true say "Installed in ${dest}." if [ -z "${SILKNEST_NO_OPEN:-}" ]; then open "$dest/SilkNest.app" say "SilkNest is running: look for the spider. Copy anything and it catches it." fi