Current behavior: Specific rules can only extend the delay set by a broader match. A rule such as com.anthropic.claudefordesktop = 0 placed above * = 3 does not take effect, even though rules are documented as evaluated top to bottom with the first match applied.
Requested behavior: The first matching rule applies as written, whether it lengthens or shortens the delay. For example:
<key>DelayAppUpdates</key>
<array>
<dict>
<key>BundleID</key>
<string>com.anthropic.claudefordesktop</string>
<key>Days</key>
<integer>0</integer>
</dict>
<dict>
<key>BundleID</key>
<string>*</string>
<key>Days</key>
<integer>3</integer>
</dict>
</array>Result: Claude updates immediately; all other apps are delayed 3 days.
Use case We want a conservative default delay across the fleet while keeping a small number of fast-moving or security-sensitive apps on the latest release. Without this, the only option is to remove the wildcard and list every app that should be delayed, which is harder to maintain and leaves newly added apps undelayed by default.
Why it matters
Matches the "first match wins" behavior described in the UI and documentation
Supports exception-based patching without giving up a safe default
Reduces admin overhead and misconfiguration risk
