Code signing policy

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

What is signed

The Windows release: qtpass.exe and the qtpass-x.y.z.exe installer. Both are built by GitHub Actions from a tagged commit in IJHack/QtPass, using the Release installers workflow, and handed to SignPath by that workflow. Nothing built on a developer's machine is signed.

The Qt libraries in the installer are Qt's own binaries and are not signed with the QtPass certificate. The macOS and Linux downloads are not covered by this certificate; every release asset carries a detached GPG signature instead (see Security).

Team roles

The IJHack organization on GitHub requires two-factor authentication for every member, and SignPath accounts use multi-factor authentication as well.

Privacy

This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. QtPass has no network code of its own; git talks to the remote you configure. Read the full privacy policy.

Checking a signature

In Explorer, right-click the installer, choose Properties → Digital Signatures, and check that the signer is SignPath Foundation. In PowerShell:

Get-AuthenticodeSignature .\qtpass-x.y.z.exe | Format-List

Report anything signed with this certificate that did not come from the QtPass releases page to help@qtpass.org.