Perhaps, but the Transmit developers could actually even use code signing to get Keychain to recognize multiple versions (new ones, but also alternative builds such as might be distributed by the Mac App Store) as the "same" application (Google "designated requirements"). Either way, though, barring security bugs (including unnecessarily permissive designated requirements being used by other apps), this should only give Transmit access to passwords you've specifically authorized for Transmit. Of course, if Transmit were malicious and one of these passwords happened to be your local login password...
Comments
Perhaps, but the Transmit developers could actually even use code signing to get Keychain to recognize multiple versions (new ones, but also alternative builds such as might be distributed by the Mac App Store) as the "same" application (Google "designated requirements"). Either way, though, barring security bugs (including unnecessarily permissive designated requirements being used by other apps), this should only give Transmit access to passwords you've specifically authorized for Transmit. Of course, if Transmit were malicious and one of these passwords happened to be your local login password...