Compare maintainable code-signing paths for an open-source Windows utility, including identity, key protection, timestamping, recurring cost, CI integration, and contributor trust boundaries.
Acceptance criteria
- Findings cite Microsoft and provider primary sources.
- No private key is placed in repository secrets or ordinary workflow logs.
- The recommendation identifies ongoing ownership and cost.
- Documentation does not instruct users to bypass SmartScreen.
- The result proposes a staged path appropriate for this project's maturity.
Compare maintainable code-signing paths for an open-source Windows utility, including identity, key protection, timestamping, recurring cost, CI integration, and contributor trust boundaries.
Acceptance criteria