Skip to content
ASTRAIL

Releases

Code signing policy

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Signing through SignPath Foundation is being set up. Until the first signed version is out, the installer is unsigned and Windows may warn you when you run it.

Last updated

What gets signed

Only official versions of Astrail: the installer and the programs it installs. They're built from the public source code in MrRobot4042212/Astrail by the repository's release workflow on GitHub Actions. Nothing built on a personal computer is signed. Programs from other projects that their authors already sign keep their own signature.

On top of that, Astrail checks the signature of every update before installing it, so it only accepts versions published by that workflow.

Team roles

Astrail has one maintainer. Anyone else contributes through pull requests, which are reviewed before they're merged.

How decisions are made and who publishes is set out in GOVERNANCE.md.

How a version is signed

  1. 1Changes are reviewed and merged into the master branch.
  2. 2Merging into the deploy branch starts the release workflow, which builds Astrail from source.
  3. 3The workflow sends the build to SignPath, and the maintainer approves each signing request by hand.
  4. 4The signed installer is published on GitHub, where this website and Astrail's built-in updater find it.

Account security

Everyone who can write to the repository or approve signing requests uses multi-factor authentication on GitHub and on SignPath.

Privacy

Astrail sends no personal data to its author. It connects to IGDB for covers, to GitHub to check for updates, and to Discord only if you turn that on. The privacy policy lists everything it sends.

Reporting a problem

If you find a signed file that doesn't come from an official version, or think the certificate is being misused, report it privately on GitHub.