Nimblesite / Nimblesite/SharpLsp
Windows code signing — current position
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 132
- Forks
- 5
- Avg merge
- 6h 24m
- Merged PRs (30d)
- 27
Description
Windows code signing — current position (Shipwright).
Native Authenticode signing is unsolved for now — we have not forgotten it and intend to do it, but there's no good long-term answer yet (a fresh cert has zero SmartScreen reputation, which can't be bought; evaluating Azure Trusted Signing later).
For now:
- Windows users should install via Scoop or Homebrew, which carry their own trust.
- Every Windows binary ships with cosign provenance for authenticity.
- Goal: get all releases onto fully-trusted Scoop + Homebrew.
Tracked for visibility — not a blocker. See https://github.com/Nimblesite/Shipwright ([SWR-SIGN-WINDOWS]).
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the Shipwright tracking entry [SWR-SIGN-WINDOWS] and review the current release-signing guidance in this issue. The scope is not ready for implementation: completion would require a decided long-term Windows signing approach and fully trusted Scoop and Homebrew releases.
Written by the indexing model from the issue text.
Assessment
- Domain
- operating-systems, release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100