OpenDMG

How to install a Mac app from GitHub, safely

By Arvind Kumar ยท

A lot of good Mac software never reaches the Mac App Store. It lives on GitHub, where the developer publishes each version as a release. Installing from there is safe when you know what to look for. This guide walks through it.

1. Find the latest release

Open the project on GitHub and look for Releases in the right-hand column. The release marked Latest is the newest stable version. A release marked Pre-release is a test build: fine if you want to try new features, not what most people want.

2. Pick the right file

Under Assets you will usually see several files. The one you want ends in .dmg or .zip. The two entries named "Source code" are the project's code, not the app, so skip them.

If the files carry a processor name, pick the one for your Mac: arm64 or "Apple silicon" for a Mac with an M-series chip, x86_64 or "Intel" for an older Mac. A file marked universal runs on both. To see which Mac you have, open the Apple menu and choose About This Mac.

3. Check the download

Many developers list a SHA-256 checksum next to their files. It is a fingerprint of the file: if yours matches, the download was not damaged or changed on the way. To get the fingerprint of your download, open Terminal and run:

shasum -a 256 ~/Downloads/TheApp.dmg

Compare the result with the one on the release page. They should match character for character.

4. Install it

For a .dmg, double-click it and drag the app onto the Applications folder, then eject the disk image. For a .zip, double-click it to unpack the app and move the app into Applications yourself.

5. Open it for the first time

macOS checks every downloaded app before it runs. This check is called Gatekeeper. If the developer signed the app with an Apple Developer ID and had it notarized by Apple, it simply opens after one confirmation.

If the app is not signed or not notarized, macOS refuses to open it. That does not mean the app is harmful, only that Apple has not checked it. If you trust the developer, open System Settings, go to Privacy and Security, scroll down, and choose Open Anyway next to the app's name. Since macOS 15 this is the only way; the old Control-click shortcut no longer works.

To see how an installed app is signed, run this in Terminal:

spctl -a -vv /Applications/TheApp.app

A notarized app answers with "accepted" and "source=Notarized Developer ID".

The short way

OpenDMG does these steps for you. You search for the app and press Get. It takes the latest release from the developer's own GitHub page, picks the file for your Mac, checks the SHA-256 fingerprint, checks the signature on your Mac, and puts the app in Applications.

Install them in one click

OpenDMG is a free, open source app store for open source Mac apps. It downloads each app from its developer's own GitHub release, checks it, and keeps it up to date. No account is needed.

Get OpenDMGBrowse all apps

Popular apps people install this way