|
| 1 | +# Code signing policy |
| 2 | + |
| 3 | +Status: application to SignPath Foundation pending. |
| 4 | + |
| 5 | +GitBoost is applying for the SignPath Foundation open-source code-signing program. Until onboarding is complete, Windows downloads remain unsigned unless their Authenticode signature verifies successfully. |
| 6 | + |
| 7 | +Free code signing provided by SignPath.io, certificate by SignPath Foundation. |
| 8 | + |
| 9 | +## Signing scope |
| 10 | + |
| 11 | +This policy covers official Windows artifacts published from the [GitBoost repository](https://github.com/DiscoverBox/gitboost): |
| 12 | + |
| 13 | +- the x64 NSIS installer (`.exe`); |
| 14 | +- the x64 MSI installer (`.msi`), when published; |
| 15 | +- the project-owned `GitBoost.exe` included in those installers. |
| 16 | + |
| 17 | +macOS artifacts are outside this Authenticode policy. Third-party components are kept under their upstream licenses and signatures and are not signed as GitBoost-owned code. |
| 18 | + |
| 19 | +Historical releases may be unsigned. A release must not be described as signed unless Windows reports a valid Authenticode signature for the downloaded artifact. |
| 20 | + |
| 21 | +## Team roles |
| 22 | + |
| 23 | +- Authors, committers, and reviewers: [DiscoverBox organization members](https://github.com/orgs/DiscoverBox/people). Trusted members may commit project-owned source and build scripts; external contributions require maintainer review before merge. |
| 24 | +- Signing approvers: [DiscoverBox organization owners](https://github.com/orgs/DiscoverBox/people?query=role%3Aowner). |
| 25 | + |
| 26 | +All maintainers and signing approvers must use multi-factor authentication for GitHub and SignPath. Every release signing request requires manual approval by a signing approver. |
| 27 | + |
| 28 | +## Trusted source, build, and release process |
| 29 | + |
| 30 | +1. The only trusted source is a version tag in the public `DiscoverBox/gitboost` repository. |
| 31 | +2. The version-controlled [GitHub Actions release workflow](https://github.com/DiscoverBox/gitboost/blob/main/.github/workflows/release.yml) runs tests and builds Windows artifacts from that tagged commit on GitHub-hosted runners. |
| 32 | +3. Product metadata must identify the application as `GitBoost`, and the artifact version must match the release tag and the version in `package.json`. |
| 33 | +4. After SignPath onboarding, only artifacts produced by that workflow may be submitted through the configured SignPath signing policy. Each request must remain traceable to its commit, tag, workflow run, and artifact. |
| 34 | +5. Signed artifacts are published on [GitHub Releases](https://github.com/DiscoverBox/gitboost/releases). Signing credentials and private keys must never be committed to the repository. |
| 35 | + |
| 36 | +## Privacy policy |
| 37 | + |
| 38 | +GitBoost does not contain analytics or advertising SDKs, does not create user accounts, and does not upload settings, routes, health history, diagnostic reports, or Git usage logs to DiscoverBox. Application data is stored locally on the user's device. |
| 39 | + |
| 40 | +GitBoost makes the following network requests to provide its requested functionality: |
| 41 | + |
| 42 | +- It retrieves the public encrypted system-node catalog from configured CDN mirrors at startup and periodically while the application is running. |
| 43 | +- It performs limited HTTPS health probes against configured acceleration nodes. Background health checks follow the interval selected by the user and can be disabled in Settings. |
| 44 | +- When acceleration is enabled, Git HTTPS reads for the user's configured public repositories are routed through the selected third-party acceleration node. That service can observe the user's IP address, the public repository path, and transferred content. |
| 45 | +- When the user starts a file download, GitBoost probes the selected acceleration URL and opens it in the user's default browser. |
| 46 | +- Project and documentation links open their public GitHub destinations in the user's default browser. |
| 47 | + |
| 48 | +These services receive normal connection metadata according to their own privacy policies. GitBoost is intended only for public GitHub repositories and must not be used for private repositories, credentials, tokens, or other sensitive content. |
| 49 | + |
| 50 | +## Verification and incident response |
| 51 | + |
| 52 | +Users should download GitBoost only from the project's GitHub Releases page and verify that any release advertised as signed has a valid Authenticode signature. If the repository, build workflow, or signing account is suspected to be compromised, maintainers will stop signing and publishing affected artifacts, investigate the incident, and work with SignPath Foundation on certificate revocation when required. |
0 commit comments