Skip to content

Stable release gate: sign macOS and Windows binaries #1

Description

@halfaipg

Scope

This issue gates a future stable validator release. It does not block the explicitly unsigned, checksum- and provenance-verified preview cohort.

v0.1.0-preview.3 is intentionally published as an immutable prerelease for Linux x64/ARM64, macOS ARM64, Windows x64, and Docker. The release page, manifest, installers, and onboarding surface warn that macOS is not Developer ID signed/notarized and Windows is not Authenticode signed. Linux and the exact versioned container are the lowest-friction operator paths. Prereleases never publish latest.

Stable-release acceptance criteria

  • Sign the macOS binary with a maintained Developer ID Application identity and hardened runtime.
  • Submit the exact distributable archive for Apple notarization and verify Gatekeeper acceptance from a fresh quarantined download.
  • Authenticode-sign the Windows binary with a maintained organizational signing identity.
  • Keep CI checks that reject ad-hoc/identity-less macOS signatures and an empty Windows certificate table for stable tags.
  • Retain SHA-256 manifest, SPDX SBOM, immutable GitHub release, and GitHub provenance attestations.
  • Run the signed stable installer from a clean macOS host and the signed Windows archive on a clean Windows host.

Do not claim an unsigned build is stable. Do not weaken checksum, SBOM, provenance, immutable-release, or exact-version requirements. Until signing is funded, continue publishing only explicitly unsigned prereleases and recommend Linux or Docker.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions