- Re-enable app-sandbox - Add network.client entitlement (required for Sparkle updates) - Keep build script passing entitlements to codesign - Use ditto for ZIP to preserve code signatures This is a minimal sandbox configuration focused on security while keeping updates working.