Content Quality: Clean, well-organized News piece with a clear Overview/What We Know/What We Don't Know structure. Subsections cover vulnerability scanning, the LaunchServices sandbox escape, Linux Landlock sandboxing, macOS/Intel tier changes, and the post_install/*flight deprecation deadline. Appropriate technical depth for the topic and category (News, 300-1200 words; article is 755 words).
Source Verification: All 3 source snapshots read in full from sources/2026-09/homebrew-700-ships-built-in-vulnerability-scanning-an-advisory-database-and-linux-landlock-sandboxing/ (gunzip, no re-fetch). sha256 of each decompressed file matched the manifest exactly. (1) source-0.html.gz — brew.sh 7.0.0 announcement (Mike McQuaid, 13 September 2026): confirms release date, the 'faster installations...Tier 3' quote verbatim, brew vulns / OSV.dev description, the advisory-database quote verbatim, CC0/OSV format claim, the LaunchServices fix description (restricting application launching, Mach services, Unix socket connections), the GHSA-rg9r-ppxp-87hm quote verbatim, the Bubblewrap-to-Landlock switch and its rationale, the 'less secure pre-6.0.0 configuration' / brew doctor advisory wording verbatim, the Big Sur / Intel Tier 3 / September 2026-2027 timeline, the BrewUI 'fully released official graphical interface for macOS' quote verbatim and its Tahoe 26 / brew install homebrew-app requirement, and the post_install/*flight deprecation deadline of 11 December 2027 with brew style --fix. All confirmed. (2) source-1.html.gz — GitHub releases/tag/7.0.0: confirms verbatim PR titles 'vulns: keep unknown subjects unresolved', 'advisory-match: derive introduced boundaries', and 'Raise minimum macOS to Big Sur (11)'. All confirmed. (3) source-2.html.gz — GHSA-5263-whxq-77hp advisory: confirms Moderate severity, CVSS overall score 6.2, affected versions <=6.0.22, patched in 7.0.0. However two passages the article presents as direct quotes ('an allow-by-default approach, denying only specific capabilities while permitting most operations' and 'This technique bypasses file-write denials and allows attackers to: Access explicitly denied paths...') are paraphrases of the advisory's Summary and Impact sections, not verbatim text — see Findings. No suspicious_patterns flagged in manifest.json for any of the three sources.
Factual Accuracy: All specific facts (dates, version numbers, CVSS score, PR titles, deadlines) check out against the snapshots. The one accuracy issue is quote fidelity, not fact fabrication: the substance of both misquoted passages (allow-by-default/blacklist sandbox model; denied paths becoming accessible, arbitrary write, and code execution once escaped) is correctly represented, but the wording inside quote marks does not match the advisory's literal text. This is a subordinate claim in the body (not the headline, summary, or lead) and does not affect the article's central thesis.
Overall Assessment: Substantively accurate, well-sourced, neutral News article on a legitimate, newly-published release. All dates, version numbers, the CVSS score, and PR titles verified verbatim against source snapshots. The only issue is that two related passages quoting the same security advisory are paraphrases dressed as direct quotes rather than fabricated facts — a subordinate, body-only issue that a single corrections note can honestly cover. Recommend APPROVE_WITH_CORRECTIONS.