TRUST / RELEASES
Code signing
policy.
How Windows releases are built, approved and signed.
Current status
Windows releases are not yet code-signed. Windows may show an unknown-publisher warning when you run the installer. Signing through the SignPath Foundation free code signing program for open-source projects is planned. This page describes the policy that signed releases will follow; it will be updated when signing is enabled.
Until then, download only from the project’s GitHub Releases and compare files with the published SHA256SUMS.txt. A checksum verifies integrity, not publisher identity.
What is signed
Only OpenSkiTime’s own release files are signed: the Windows installer and the OpenSkiTime executables and libraries it contains. They are built from the public source repository by GitHub Actions from a protected vX.Y.Z tag on the reviewed master branch. Locally built files and files from forks are never signed.
Third-party components distributed with OpenSkiTime, such as the .NET runtime, keep their upstream publishers’ signatures and are not re-signed as OpenSkiTime. Vendor drivers and SDKs, such as ALGE software, are not distributed or signed by this project.
Team roles
- Committers and reviewers: Teemu Niemi (@tnakeli), maintainer. Changes from other contributors are merged only through reviewed pull requests.
- Approvers: Teemu Niemi (@tnakeli). Each signing request is approved manually for a specific release.
All team members use multi-factor authentication for GitHub and for the signing service.
Release process
Each release passes automated build, test, installer, dependency (SBOM) and vulnerability checks before it is published. High and critical known vulnerabilities block publication. Release notes are published with every version, and release tags are never moved after publication.
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. Online features such as FIS lookups, weather forecasts and live publishing are started by the operator. See Privacy & your race data for details.
Report a problem
If you find a signed file that you believe was not released by this project, or another security issue, report it privately through GitHub security advisories.