TRUST & RELEASES
Code signing policy
Current status: version 0.18.0 is a verified but unsigned preview. No file is presented as signed until its signature and timestamp have been independently verified.
Provider statement
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
Project roles
- Committers and reviewers: pusmartinczech-ship-it
- Signing approver: pusmartinczech-ship-it
What may be signed
Only Nettongia PDF Editor release artifacts built by the repository's GitHub Actions workflow from an identified source revision may be submitted. Upstream libraries are included under their own licenses and are not presented as Nettongia-authored binaries.
Release procedure
- All source and build-script changes are committed to the project repository.
- The Windows workflow builds from a clean hosted runner with hash-pinned dependencies and bundled OCR assets.
- Source regression, frozen self-test, golden-PDF comparison, memory soak and clean portable OCR acceptance must pass.
- A trusted approver manually approves each signing request.
- The signature, timestamp, product metadata and published SHA-256 values are verified before release.
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. See the privacy policy.
Security reports
Please use GitHub private vulnerability reporting for sensitive security issues. Ordinary defects belong in the public issue tracker after the repository is published.
Policy version 1.0 · 14 September 2026