Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ npm run llms
```

This validates that every page in `docs.json` exists and every page on disk is
reachable from the navigation. CI additionally runs a link check.
reachable from the navigation. CI also runs a link check.

## Conventions

Expand Down
2 changes: 1 addition & 1 deletion introduction.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ actually links. Start at [Static analysis](/static-analysis).
**Dynamic analysis** means launching the app under observation and watching
what it does: file events, network destinations, child processes, pasteboard
and camera and microphone access. That needs the
[privileged helper](/privileged-helper), and for anything you genuinely don't
[privileged helper](/privileged-helper), and for anything you don't
trust, it should happen inside [VM mode](/vm-mode).

## What it won't do
Expand Down
2 changes: 1 addition & 1 deletion kill-switch.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ description: "Cut the inspected app's outbound traffic system-wide, and watch ho
During a [monitored run](/monitored-runs) you can block the destinations the
inspected app has been contacting, then watch what it does about it.

This is a genuinely useful test. An app that degrades gracefully when its
An app that degrades gracefully when its
analytics endpoint disappears behaves very differently from one that blocks the
UI, retries in a tight loop, or refuses to start.

Expand Down
14 changes: 7 additions & 7 deletions llms-full.txt

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

8 changes: 4 additions & 4 deletions static-analysis.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@ title: Static analysis
description: "What privacycommand extracts from a bundle without running it — the bulk of the report."
---

Static analysis reads the bundle on disk. Nothing executes, so this is the part
you can safely run against something you don't trust at all.
Static analysis reads the bundle on disk without executing it, so you can run it
against a bundle you don't trust.

It is also where most of the report comes from. Roughly forty detectors run over
a bundle; this page groups them by the question they answer.
Expand All @@ -19,8 +19,8 @@ a bundle; this page groups them by the question they answer.
recognise.
</Accordion>
<Accordion title="Notarization" icon="stamp">
A deep dive rather than a yes/no: whether the ticket is stapled, what
`spctl` says about it, and the SHA-256 of the bundle. Every relaxation is
This check reports whether the ticket is stapled, what `spctl` says about
it, and the SHA-256 of the bundle. Every relaxation is
reported with the entitlement or flag responsible.
</Accordion>
<Accordion title="Provenance" icon="tag">
Expand Down
2 changes: 1 addition & 1 deletion vm-mode.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: VM mode
description: "Run the analysis inside a disposable macOS VM, and ship the observations back to your Mac."
---

For a bundle you genuinely don't trust, running it on your own machine is the
For a bundle you don't trust, running it on your own machine is the
wrong move — even under observation. VM mode moves the execution into a
disposable macOS guest and streams the results back.

Expand Down
Loading