The macOS gh binary is ad-hoc signed without hardened runtime:
$ codesign -dvv $(which gh)
flags=0x20002(adhoc,linker-signed)
This means any process can inject code into gh via DYLD_INSERT_LIBRARIES and intercept HTTP requests, including authentication headers.
Developer workstations are increasingly targeted by supply chain attacks that exploit developer tooling. The gh CLI is a high-value target because it handles GitHub API authentication.
Signing with --options runtime would block this. macOS prevents dylib injection into hardened runtime binaries by default.
codesign --sign "Developer ID Application: ..." --options runtime --timestamp gh
Related: #9139 (installer signing), #2176 (FIDO2 for API auth)
The macOS
ghbinary is ad-hoc signed without hardened runtime:This means any process can inject code into
ghviaDYLD_INSERT_LIBRARIESand intercept HTTP requests, including authentication headers.Developer workstations are increasingly targeted by supply chain attacks that exploit developer tooling. The
ghCLI is a high-value target because it handles GitHub API authentication.Signing with
--options runtimewould block this. macOS prevents dylib injection into hardened runtime binaries by default.codesign --sign "Developer ID Application: ..." --options runtime --timestamp ghRelated: #9139 (installer signing), #2176 (FIDO2 for API auth)