Skip to content
Code signing policy

Code signing policy

Free code signing provided by SignPath.io, certificate by SignPath Foundation

What is signed

The signed files are the Windows executables sortie.exe for amd64 and arm64. Each ships inside its release archive, sortie_VERSION_windows_amd64.zip or sortie_VERSION_windows_arm64.zip, on the GitHub Releases page. The archives and the hashes in checksums.txt are produced after signing, so they cover the signed executable.

Every signed executable is built from the source in the sortie-ai/sortie repository by the project’s release workflow on GitHub-hosted runners. That workflow is the only place a signing request is submitted.

The Linux and macOS archives, the Docker image, and any binary built with go install or from source are not signed through this program.

Team roles

RoleMembersWhat the role does
CommittersSerghei Iakovlev (@sergeyklay, @serghei-dev)Maintain the repository and merge changes into main.
ReviewersSerghei Iakovlev (@sergeyklay, @serghei-dev)Default code owners in CODEOWNERS. A change from anyone else reaches main only through a pull request with an approving code-owner review.
ApproversSerghei Iakovlev (@sergeyklay, @serghei-dev)Manually approve every signing request before SignPath signs it.

@serghei-dev is a second GitHub account of the same person.

Privacy

This program will not transfer any information to other networked systems unless specifically requested by the person installing or operating it. A running instance connects only to the endpoints its configuration names, such as the issue tracker, the code forge, and notification URLs, and it sends no telemetry, analytics, or update checks. The coding agent Sortie launches is a separate program with its own privacy policy. Outbound data posture has the details.

Was this page helpful?