Security advisory
GPT-6 Astra passed
- Tokens
- 62,855
- Cost
- $0.59
Write a security advisory from the Norvane security team to people who use Norvane Forge on macOS. It is an action-required notice: recipients must update before a deadline or the app stops working. Subject: Action required: security update for Norvane Forge on macOS. Preview text: Update Norvane Forge for macOS before June 12, 2026 to avoid losing access.
Open with the Norvane mark (assets.mark, with assets.markDark for dark mode), then a headline that says action is required and names Norvane Forge on macOS.
The facts to cover:
- Recipients must update Norvane Forge for macOS before June 12, 2026 to avoid disruption of access. Any app or CLI that is not updated by then will be blocked until it is updated.
- What happened, in plain terms: as a precautionary security measure, the Norvane security team rotated the code signing certificate for Norvane Forge on macOS. Builds signed with the old certificate will stop being trusted on June 12. There is a blog post with the details (https://norvane-email.s3.amazonaws.com/blog/forge-macos-signing-update).
- Norvane found no evidence that user data was accessed, that its systems were compromised, or that its software was altered. The rotation was done out of an abundance of caution.
- Norvane Forge on Windows and Linux, the Forge browser extension, and the Forge CLI on Windows and Linux are not affected.
- Affected versions and minimum safe versions, shown side by side so each product's affected range sits next to its minimum safe version, with version numbers in monospace:
- Norvane Forge app for macOS: versions 3.4.0 through 3.7.2 are affected; the minimum safe version is 3.8.0.
- Forge CLI on macOS: versions before 1.19.0 are affected; the minimum safe version is 1.19.0.
- How to update, as numbered steps:
- Forge app: open the Norvane Forge menu and choose Check for Updates, or download the latest build (https://norvane-email.s3.amazonaws.com/forge/update). The download link is the primary button.
- Forge CLI: run
npm install -g @norvane/forge-cli@latestin a terminal. The command is set as a monospace code block. The CLI update guide has other install methods (https://norvane-email.s3.amazonaws.com/docs/forge/cli-update). - Confirm the version: About Norvane Forge in the app menu should show 3.8.0 or later, and
forge --versionshould print 1.19.0 or later.
- Recipients do not need to reset their Norvane password or rotate their Norvane API keys.
- Questions go to security-response@norvane.ai.
Sign off as The Norvane Security Team.
The footer is the transactional footer from the world: Console, Docs, and Support links, the postal address, the copyright line, and Privacy and Terms links. No unsubscribe link; this is a service notice.
Dark mode should be supported.
Use /world/norvane-email for brand chrome and CSS. Use the absolute HTTPS URLs from tokens.json; do not use /world/ paths as image src.
Leave the HTML in output/email.html, a plain-text version in output/email.txt, and the subject in output/meta.json as {"subject": "..."}. Don't include From, To, or Date headers.