Code-signing policy
Wirebench releases are built only by the project’s release workflow, from a version tag in the public repository. Nothing is built or signed on a developer’s machine.
Windows
Section titled “Windows”Windows releases are signed with Microsoft’s Azure Artifact Signing service, under a Public Trust certificate profile. The release workflow signs in to Azure through GitHub’s OpenID Connect, so no signing key or client secret is stored in the repository or on a developer’s machine.
- What is signed: the program files (
Wirebench.exeand the other executables it ships) and the installers built around them (…-setup.exeand.msi), for x64 and arm64. - Who approves: only the release workflow may sign, and every release stays a draft until an approver named under Team roles publishes it.
- What the workflow checks first: a release is built only after the project’s full check suite
(
pnpm check) passes.
Windows signing is being set up. Releases up to and including 5.0.0 ship unsigned Windows installers, so Windows names an unknown publisher when they run.
Team roles
Section titled “Team roles”| Role | Who | What the role covers |
|---|---|---|
| Authors | Mohammed Naami (@mnaami) | Trusted to change the source code without a further review. |
| Reviewers | Mohammed Naami (@mnaami) | Review every change proposed by someone who is not an author before it is merged. |
| Approvers | Mohammed Naami (@mnaami) | Review and publish each release. |
Everyone in these roles uses multi-factor authentication on GitHub and on Azure.
Releases are signed with the project’s Apple Developer ID Application certificate and notarised by Apple, so Gatekeeper opens them without a warning.
Every release
Section titled “Every release”- Releases are created as drafts. A maintainer reviews the draft and publishes it by hand.
- Each file carries a GitHub build attestation that links it to the commit and workflow run that built it. Each release also includes a CycloneDX SBOM of the app’s dependencies. See Verify a download.
- The app talks to no server of the project’s own. Update checks go to GitHub Releases, and only when you ask for one or turn on checking at launch, which is off by default.
Privacy
Section titled “Privacy”This program will not transfer any information to other networked systems unless specifically requested by the user.
Wirebench sends no telemetry and collects no data. The requests it sends are the ones you send. See the FAQ.