Skip to content

chore: set up code signing for releases #84

Description

@nextestudios

Summary

Sign the installer and portable executable (e.g. an open-source signing service) so SmartScreen warnings decrease.

Motivation

Unsigned binaries trigger SmartScreen; docs/CODE_SIGNING.md already states the policy.

Requirements

  • Only tag builds signed, from CI; certificate never stored in the repository; manual approval step.
  • Verify Authenticode in the release workflow before publishing.

Controller UX

N/A.

Technical Notes

Release workflow step similar to the existing manifest signing.

Acceptance Criteria

  • Published binaries have a valid Authenticode signature.

Testing

Release workflow verification.

Dependencies

  • None

Priority: medium · Milestone: 9 · 1.0 Readiness

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: releasePackaging, signing, CI and releasesmoscow: shouldMoSCoW: important, planned for 1.0 if time allowstype: featureNew capability

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions