TRUST / RELEASES

Code signing
policy.

How Windows releases are built, approved and signed.

Current status

Windows releases are not yet code-signed. Windows may show an unknown-publisher warning when you run the installer. Signing through the SignPath Foundation free code signing program for open-source projects is planned. This page describes the policy that signed releases will follow; it will be updated when signing is enabled.

Until then, download only from the project’s GitHub Releases and compare files with the published SHA256SUMS.txt. A checksum verifies integrity, not publisher identity.

What is signed

Only OpenSkiTime’s own release files are signed: the Windows installer and the OpenSkiTime executables and libraries it contains. They are built from the public source repository by GitHub Actions from a protected vX.Y.Z tag on the reviewed master branch. Locally built files and files from forks are never signed.

Third-party components distributed with OpenSkiTime, such as the .NET runtime, keep their upstream publishers’ signatures and are not re-signed as OpenSkiTime. Vendor drivers and SDKs, such as ALGE software, are not distributed or signed by this project.

Team roles

All team members use multi-factor authentication for GitHub and for the signing service.

Release process

Each release passes automated build, test, installer, dependency (SBOM) and vulnerability checks before it is published. High and critical known vulnerabilities block publication. Release notes are published with every version, and release tags are never moved after publication.

Privacy

This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. Online features such as FIS lookups, weather forecasts and live publishing are started by the operator. See Privacy & your race data for details.

Report a problem

If you find a signed file that you believe was not released by this project, or another security issue, report it privately through GitHub security advisories.