Code signing policy

Effective and last updated: July 20, 2026

Signing service and scope

Current releases are unsigned.

The project has applied to SignPath Foundation. Approval and signing integration are pending; SignPath does not currently provide signing for StreamDecky releases.

This policy covers official Windows release builds of StreamDecky.exe published through GitHub Releases. The ZIP archive is accompanied by a SHA-256 checksum. If signing is approved and integrated, the executable inside the archive will be the Authenticode-signed artifact; ZIP archives themselves are not Authenticode-signable.

Each release's notes state its actual signing status and are authoritative for that release. The policy will be updated only after signing is integrated and a published signature has been verified.

Project roles

Contributions from people without commit access are reviewed before they are merged. If signing is integrated, every signing request will require manual approval by the signing approver. Multi-factor authentication is required for accounts with source-control access and will be required for signing access.

Source and build provenance

Official releases are built from the public StreamDecky repository by the checked-in GitHub Actions release workflow on GitHub-hosted Windows runners. The workflow restores declared dependencies, runs the test suite, publishes the self-contained Windows executable, verifies signing when enabled, packages the release, and produces a SHA-256 checksum. Only artifacts originating from this automated release workflow are eligible for SignPath signing.

Privacy

StreamDecky's network communication and local data handling are documented in the StreamDecky privacy policy.

Reporting concerns

Report suspected signature misuse, compromised releases, or policy violations through the project issue tracker. Reports concerning a SignPath Foundation certificate may also be sent to support@signpath.io.