Code signing policy
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
What is signed
The Windows release: qtpass.exe and the
qtpass-x.y.z.exe installer. Both are built by GitHub
Actions from a tagged commit in
IJHack/QtPass, using the
Release installers
workflow, and handed to SignPath by that workflow. Nothing built on a
developer's machine is signed.
The Qt libraries in the installer are Qt's own binaries and are not signed with the QtPass certificate. The macOS and Linux downloads are not covered by this certificate; every release asset carries a detached GPG signature instead (see Security).
Team roles
-
Committers and reviewers: the
IJHack members with write
access to the QtPass repository. Every change reaches
mainthrough a pull request with signed commits that has passed CI and automated review; committers merge their own changes, and contributions from outside the team are reviewed by a committer before they are merged. - Approvers: Anne Jan Brouwer. Every signing request waits for manual approval in SignPath before anything is signed.
The IJHack organization on GitHub requires two-factor authentication for every member, and SignPath accounts use multi-factor authentication as well.
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. QtPass has no network code of its own; git talks to the remote you configure. Read the full privacy policy.
Checking a signature
In Explorer, right-click the installer, choose Properties → Digital Signatures, and check that the signer is SignPath Foundation. In PowerShell:
Get-AuthenticodeSignature .\qtpass-x.y.z.exe | Format-List
Report anything signed with this certificate that did not come from the QtPass releases page to help@qtpass.org.