Code signing policy
Last updated:
FaamOffice has submitted an application to the SignPath Foundation free code signing program and is awaiting a response (pending). The project has not been accepted, and no release has a SignPath signature.
1. Application status
Current status: application submitted, awaiting a response (pending), as confirmed by the maintainer. Credit SignPath as a signing provider only after the project has been accepted; document each release's signature status separately in its release notes.
2. Responsible team members
dinhthaicx maintains the project, reviews code and approves releases: https://github.com/dinhthaicx
- Maintainer: dinhthaicx.
- Reviewer: dinhthaicx.
- Release approver: dinhthaicx.
3. Source code and release process
Public source code and GitHub Actions builds: https://github.com/dinhthaicx/faamoffice. FaamOffice is a fork of GenOffice and must be reviewed by SignPath under its conditions for modified upstream code.
If accepted, every signing request must be approved by the release approver before publication. Participants in signing must use multi-factor authentication for GitHub and SignPath. SignPath signing is not currently integrated into the release process.
4. Signatures on existing packages
The Windows installer on GitHub currently has no Authenticode signature. The macOS 0.11.2 installers are Apple Developer ID signed and notarized; that is Apple signing, not SignPath. The AppX package is being prepared for Microsoft Store submission; Microsoft signs Store-distributed packages after approval.
5. Privacy and contact
Privacy policy: https://faamoffice.net/en/privacy. Application network disclosure: https://github.com/dinhthaicx/faamoffice/blob/faamoffice/PRIVACY.md.
Questions about signing and releases: https://github.com/dinhthaicx/faamoffice/issues.