← Home / Domů

TRUST & RELEASES

Code signing policy

Current status: version 0.18.0 is a verified but unsigned preview. No file is presented as signed until its signature and timestamp have been independently verified.

Provider statement

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Project roles

What may be signed

Only Nettongia PDF Editor release artifacts built by the repository's GitHub Actions workflow from an identified source revision may be submitted. Upstream libraries are included under their own licenses and are not presented as Nettongia-authored binaries.

Release procedure

  1. All source and build-script changes are committed to the project repository.
  2. The Windows workflow builds from a clean hosted runner with hash-pinned dependencies and bundled OCR assets.
  3. Source regression, frozen self-test, golden-PDF comparison, memory soak and clean portable OCR acceptance must pass.
  4. A trusted approver manually approves each signing request.
  5. The signature, timestamp, product metadata and published SHA-256 values are verified before release.

Privacy

This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. See the privacy policy.

Security reports

Please use GitHub private vulnerability reporting for sensitive security issues. Ordinary defects belong in the public issue tracker after the repository is published.

Policy version 1.0 · 14 September 2026