It's ridiculous that my open source code is hosted on GitHub, the binary is created with an action but I have to pay for a certificate and manually sign it.
It's ridiculous that my open source code is hosted on GitHub, the binary is created with an action but I have to pay for a certificate and manually sign it.
Idea being that one could, in theory, download the git repo, check out the relevant commit and verify that this was the source code and this was the resulting binary, and that matches the exe file I just downloaded.
With the current setup GitHub has more control on the resulting bits than I do.
Also, current Microsoft signature rules that a hardware dongle is required to sign the bits (all non-hardware certificates will be deprecated in time).
So, I'm supposed to take the .EXE that GitHub produced on one of their VMs running actions then certify it's legit by signing it with my certificate.
But what am I actually certifying? Well, that to the best of my knowledge this EXE is the build output of this Git commit that triggered the action.