Earlier quoted context omitted.
> What else is the scanning of an uploaded executable than an (automated) review process though? It's a pass of checks that might or might not find something. It's not some official stamp of approval, except to say "those checks passed ok".
"Those checks passed ok" is an approval in itself. The notarization process has the outcome of either being approved or being denied. Approved means "officially agreed or accepted as satisfactory.".
Notarisation for macOS similarly only means, “the developer presented us with their application and their certificate of authenticity and we signed it with the certificate that allows macOS to run it without complaining.”
There’s no attempt by Apple to claim that the application is safe or does what it says on the tin.
Scanning for malware is simply to avoid embarrassing situations me an author/publisher finding they’ve been compromised by some well known malware.
The outcome of notarisation is that the app has been notarised.
It’s like claiming that the outcome of toasting a sandwich is approval or rejection, no the outcome of toasting a sandwich is you have a sandwich that is toasted, aka “toasted sandwich.”
You might reject a sandwich which isn’t built properly (eg: has mismatched bread slices, is missing contents or smells of dynamite). But toasting the sandwich provided by the customer doesn’t mean you actually like it.