Skip to content

Commit bb31140

Browse files
committed
docs: prepare SignPath application
1 parent 7dc93fd commit bb31140

3 files changed

Lines changed: 68 additions & 0 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -65,6 +65,14 @@ jobs:
6565
6666
- macOS: Apple Silicon DMG
6767
- Windows: NSIS EXE / MSI
68+
69+
## Code signing policy
70+
71+
GitBoost is applying for the SignPath Foundation open-source code-signing program. Treat an artifact as signed only when its Authenticode signature verifies successfully.
72+
73+
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
74+
75+
See the [Code signing policy](https://github.com/DiscoverBox/gitboost/blob/main/CODE_SIGNING_POLICY.md).
6876
releaseDraft: true
6977
prerelease: false
7078
args: --target ${{ matrix.target }}

‎CODE_SIGNING_POLICY.md‎

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
# Code signing policy
2+
3+
Status: application to SignPath Foundation pending.
4+
5+
GitBoost is applying for the SignPath Foundation open-source code-signing program. Until onboarding is complete, Windows downloads remain unsigned unless their Authenticode signature verifies successfully.
6+
7+
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
8+
9+
## Signing scope
10+
11+
This policy covers official Windows artifacts published from the [GitBoost repository](https://github.com/DiscoverBox/gitboost):
12+
13+
- the x64 NSIS installer (`.exe`);
14+
- the x64 MSI installer (`.msi`), when published;
15+
- the project-owned `GitBoost.exe` included in those installers.
16+
17+
macOS artifacts are outside this Authenticode policy. Third-party components are kept under their upstream licenses and signatures and are not signed as GitBoost-owned code.
18+
19+
Historical releases may be unsigned. A release must not be described as signed unless Windows reports a valid Authenticode signature for the downloaded artifact.
20+
21+
## Team roles
22+
23+
- Authors, committers, and reviewers: [DiscoverBox organization members](https://github.com/orgs/DiscoverBox/people). Trusted members may commit project-owned source and build scripts; external contributions require maintainer review before merge.
24+
- Signing approvers: [DiscoverBox organization owners](https://github.com/orgs/DiscoverBox/people?query=role%3Aowner).
25+
26+
All maintainers and signing approvers must use multi-factor authentication for GitHub and SignPath. Every release signing request requires manual approval by a signing approver.
27+
28+
## Trusted source, build, and release process
29+
30+
1. The only trusted source is a version tag in the public `DiscoverBox/gitboost` repository.
31+
2. The version-controlled [GitHub Actions release workflow](https://github.com/DiscoverBox/gitboost/blob/main/.github/workflows/release.yml) runs tests and builds Windows artifacts from that tagged commit on GitHub-hosted runners.
32+
3. Product metadata must identify the application as `GitBoost`, and the artifact version must match the release tag and the version in `package.json`.
33+
4. After SignPath onboarding, only artifacts produced by that workflow may be submitted through the configured SignPath signing policy. Each request must remain traceable to its commit, tag, workflow run, and artifact.
34+
5. Signed artifacts are published on [GitHub Releases](https://github.com/DiscoverBox/gitboost/releases). Signing credentials and private keys must never be committed to the repository.
35+
36+
## Privacy policy
37+
38+
GitBoost does not contain analytics or advertising SDKs, does not create user accounts, and does not upload settings, routes, health history, diagnostic reports, or Git usage logs to DiscoverBox. Application data is stored locally on the user's device.
39+
40+
GitBoost makes the following network requests to provide its requested functionality:
41+
42+
- It retrieves the public encrypted system-node catalog from configured CDN mirrors at startup and periodically while the application is running.
43+
- It performs limited HTTPS health probes against configured acceleration nodes. Background health checks follow the interval selected by the user and can be disabled in Settings.
44+
- When acceleration is enabled, Git HTTPS reads for the user's configured public repositories are routed through the selected third-party acceleration node. That service can observe the user's IP address, the public repository path, and transferred content.
45+
- When the user starts a file download, GitBoost probes the selected acceleration URL and opens it in the user's default browser.
46+
- Project and documentation links open their public GitHub destinations in the user's default browser.
47+
48+
These services receive normal connection metadata according to their own privacy policies. GitBoost is intended only for public GitHub repositories and must not be used for private repositories, credentials, tokens, or other sensitive content.
49+
50+
## Verification and incident response
51+
52+
Users should download GitBoost only from the project's GitHub Releases page and verify that any release advertised as signed has a valid Authenticode signature. If the repository, build workflow, or signing account is suspected to be compromised, maintainers will stop signing and publishing affected artifacts, investigate the incident, and work with SignPath Foundation on certificate revocation when required.

‎README.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,14 @@ GitBoost 不提供代理服务。它只检测第三方线路,并通过独立
7474
>
7575
> macOS 包未使用 Apple Developer ID 证书签名,也未经过 Apple 公证。Windows 包未配置发布者代码签名,可能显示“发布者未知”或触发 SmartScreen。请只从本项目的 [GitHub Releases](https://github.com/DiscoverBox/gitboost/releases) 下载。
7676
77+
### Code signing policy
78+
79+
GitBoost 正在申请 SignPath Foundation 的开源代码签名服务。申请和接入完成前,Windows 安装包仍按未签名软件处理;只有 Windows 显示 Authenticode 签名有效的发布包才可视为已签名。
80+
81+
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
82+
83+
签名范围、负责人、可验证构建流程和隐私说明见 [Code signing policy](CODE_SIGNING_POLICY.md)。
84+
7785
## 用户手册
7886

7987
安装、首次启用、线路确认、环境诊断和恢复配置见 [GitBoost 用户手册](docs/USER_GUIDE.md)。

0 commit comments

Comments
 (0)