tsudev # Code signing policy tsudev.com
--- ## Team roles `tsudev-cwico` is maintained by a single person, who therefore holds all three roles. Should the project gain additional maintainers, this section is updated before their first merge. | Role | Who | What they may do | |---|---|---| | **Author** | [@tsudev-tsudev](https://github.com/tsudev-tsudev) (Dev Tsu) | Commit directly to `main` | | **Reviewer** | [@tsudev-tsudev](https://github.com/tsudev-tsudev) (Dev Tsu) | Approve contributions from outside the team | | **Approver** | [@tsudev-tsudev](https://github.com/tsudev-tsudev) (Dev Tsu) | Authorise a release build to be signed | All accounts with write access to the repository, and to any signing service, have multi-factor authentication enabled. ## What gets signed, and from what Only artefacts built by [`.github/workflows/release.yml`](../.github/workflows/release.yml) from a tagged commit on `main` in [tsudev-tsudev/tsudev-cwico](https://github.com/tsudev-tsudev/tsudev-cwico) are signed. Nothing is built locally and uploaded, and no third-party binary is ever signed with this project's identity. The build is reproducible in the sense that matters for review: the workflow, the manifests and every input are in the repository, and the tag it built from is recorded on the release. Build scripts and CI configuration are held to the same review standard as the application source, because a change to `release.yml` is a change to what gets signed. ## Two signatures, two purposes | | Update signing | Code signing | |---|---|---| | Purpose | Installed copies only accept updates published by this project | Windows recognises the publisher; no SmartScreen warning | | Status | **In place** | **Applied for** - see below | | Key custody | Ed25519 key generated by the maintainer, private half in GitHub repository secrets and offline backup | Held in an HSM by the signing provider; never exported | Details of both: [`SIGNING.md`](SIGNING.md). ### Code signing provider An application has been made to the [SignPath Foundation](https://signpath.org/), which provides free code signing certificates to qualifying open-source projects. Until it is accepted, released installers are **unsigned** and Windows SmartScreen warns on first run - this is stated in the release notes rather than left for users to discover. *This section is updated with the appropriate attribution once the application is accepted; it is not claimed in advance.* ## Privacy - what the software collects **Nothing.** This is a deliberate design commitment, not a current state of affairs that might change quietly: * The application makes **no outbound network connections** except the update check described below. * It sends **no telemetry, no analytics, no crash reports and no usage data**, to this project or to anyone else. * It has **no account, no login and no licence check**. * Scan results, the inventory of installed software, and the transaction logs of what was removed **never leave the machine**. They are written to `%LOCALAPPDATA%\tsudev-cwico\` and read by nothing but the user. ### The one network request On startup the application fetches `https://github.com/tsudev-tsudev/tsudev-cwico/releases/latest/download/latest.json` to learn whether a newer release exists. This is a static file on GitHub's CDN. The request carries nothing about the user or their machine beyond what any HTTP request unavoidably reveals to the server serving it - GitHub's privacy policy governs what GitHub does with that. If the request fails, the application starts normally. Nothing else is fetched, and nothing is ever sent. These commitments are also recorded in [`../SECURITY.md`](../SECURITY.md), where a change to any of them is treated as a security-relevant change. ## Reporting a problem with a signed artefact If you believe a binary signed with this project's identity is not what this repository built, please report it privately: [security advisory](https://github.com/tsudev-tsudev/tsudev-cwico/security/advisories/new) or security@tsudev.com. That is the highest-priority class of report this project accepts.