microsoft / microsoft/winget-pkgs

[New Feature]: Verified Developer for WinGet Community Repository

Open
#325,096 7 comments 8 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Issue-Feature
Dominant language
No language data
Stars
11.1k
Forks
9.7k
Avg merge
1h 32m
Merged PRs (30d)
616

Description

### Description of the new feature/enhancement

I want to know the package I'm considering installing comes from the developer.

Initially, this will be implemented for Microsoft packages in the WinGet Community Repository. These packages will be submitted for validation and will be subject to the same policies other manifests in the community repository, but when the PR is made to GitHub it will not require an additional validation. Instead, these PRs will be merged as approved and will not require community moderation. Changes or submissions will not be allowed by PRs from other contributors.

Once the end-to-end flows have been implemented and the WinGet client can provide the appropriate indication, we will begin work on the processes for other developers/publishers.

> [!Important]
> The technical implementation for this has not been the reason for delay. The larger concern is how a developer is verified.

> [!Note]
> This was implemented but due to the lack of business processes it has not been enabled:
> * #100

### Proposed technical implementation details (optional)

_No response_

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with issue #100, which is cited as the prior implementation, and review the described Microsoft-package submission and approval flow. The scope still depends on defining how developers are verified; done means the end-to-end flow is implemented, the WinGet client shows the appropriate indication, and verified submissions follow the stated approval and contribution restrictions.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
release, tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.