Code signing policy
Where the build comes from.
Every AngKorGit release is built by GitHub Actions from a tag on the public repository. Nothing is built on a laptop and uploaded by hand. This page is the code signing policy for those builds: who is allowed to produce them, how the Windows installer gets its signature, and what the app does with your data once it is running.
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
How a release is built
A release starts as a v* tag on main. The
release workflow
checks out that tag, installs the pinned dependencies from the lockfiles, runs the Tauri bundler on macOS, Windows
and Linux runners, and attaches the result to a draft GitHub release. The workflow file is part of the repository,
so the build steps are reviewed like any other change.
The Windows installer and .msi are then submitted to SignPath from inside that same workflow run.
SignPath checks that the artifact came from a GitHub Actions run of this repository before it signs anything, and
the signing request waits for a manual approval. Only after the signed files come back does the release get
published. Updates the app downloads for itself carry a second signature, a minisign key held by the maintainer,
which the updater verifies before it installs anything.
The signed binaries are built only from this repository’s own source and build scripts. Third party crates and npm packages are compiled in, unmodified, from the versions in the lockfiles.
Who does what
AngKorGit is maintained by one person, so the three roles below are mostly the same account. Each one still has its own job, and two factor authentication is required on GitHub and on SignPath for anyone holding a role.
- Author
- Chansocheat Sok (cheat2001) and the contributors whose pull requests are merged writes the code and opens pull requests.
- Reviewer
- Chansocheat Sok (cheat2001) reviews every change before it lands on main. Contributor pull requests are squashed under the contributor’s name after review.
- Approver
- Chansocheat Sok (cheat2001) tags the release, publishes it and approves the signing request for each release.
Checking a download
On Windows, right click the installer, open Properties and the Digital Signatures tab. The signer reads SignPath Foundation. On every platform, the releases page is the only place builds are published, and the Homebrew cask pins the SHA-256 of the macOS disk image. If a download looks wrong, do not run it, and report it.
Releases before the first signed one are unsigned. They were built by the same workflow, but Windows cannot tell, which is why SmartScreen calls the publisher unknown on those versions.
Privacy
AngKorGit has no telemetry and no analytics. It never phones home, there is no account, and nothing you do in the app is reported anywhere. The program does connect to other systems, but only the ones you point it at:
- The Git remotes of the repositories you open, for fetch, pull, push and clone.
- GitHub, GitLab or Bitbucket, only after you connect an account in Settings, for pull requests and avatars.
- Gravatar, to look up commit author avatars by a hash of the email address.
- The AI provider you choose in Settings, and only the text of the change you ask it about. Nothing is sent until you click.
- GitHub Releases, shortly after launch, to ask whether a newer signed build exists.
Account tokens and AI provider keys live in your operating system keychain. Settings and recent repositories stay on your machine. The full list of what the app touches, and how to report a security problem, is in SECURITY.md.
Installing and removing
The installers change nothing outside their own install folder and the usual shortcuts. The optional command line tool, added from Settings, puts a small shim on your PATH and says where. Uninstall through the same channel you installed with: the Windows uninstaller, dragging the app out of Applications, Homebrew, or your Linux package manager, and the shim is removed from Settings.