Code signing policy
Effective and last updated: July 20, 2026
Signing service and scope
Current releases are unsigned.
The project has applied to SignPath Foundation. Approval and signing integration are pending; SignPath does not currently provide signing for MicMixer releases.
This policy covers official Windows release builds of MicMixer.exe published through
GitHub Releases. The ZIP archive
is accompanied by a SHA-256 checksum. If signing is approved and integrated, the executable
inside the archive will be the Authenticode-signed artifact; ZIP archives themselves are not
Authenticode-signable.
Each release's notes state its actual signing status and are authoritative for that release. The policy will be updated only after signing is integrated and a published signature has been verified.
Project roles
- Author and committer: BenjiButten (@benjibutten)
- Reviewer: BenjiButten (@benjibutten)
- Future signing approver: BenjiButten (@benjibutten)
Contributions from people without commit access are reviewed before they are merged. If signing is integrated, every signing request will require manual approval by the signing approver. Multi-factor authentication is required for accounts with source-control access and will be required for signing access.
Source and build provenance
Official releases are built from the public MicMixer repository by the checked-in GitHub Actions release workflow on GitHub-hosted Windows runners. The workflow restores declared dependencies, publishes the self-contained Windows executable, verifies signing when enabled, packages the release, and produces a SHA-256 checksum. Only artifacts originating from this automated release workflow are eligible for SignPath signing.
Privacy
MicMixer's network communication and local data handling are documented in the MicMixer privacy policy.
Reporting concerns
Report suspected signature misuse, compromised releases, or policy violations through the project issue tracker. Reports concerning a SignPath Foundation certificate may also be sent to support@signpath.io.