Code signing policy
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
What is signed
The Windows release: qtpass.exe and the
qtpass-x.y.z.exe installer. Both are built by GitHub
Actions from a tagged commit in
IJHack/QtPass, using the
Release installers
workflow, and handed to SignPath by that workflow. Nothing built on a
developer's machine is signed.
The Qt libraries in the installer are Qt's own binaries and are not signed with the QtPass certificate.
Status per platform
- Windows: signing through SignPath is set up and tested. The SignPath Foundation is reviewing the setup before it issues the production certificate; until then the installer is unsigned and SmartScreen asks for More info → Run anyway on first start. Progress: #1643.
-
macOS: the
.dmgis not signed or notarized. That needs an Apple Developer ID, a paid Apple Developer Program membership the project does not have, so Gatekeeper blocks the first launch and the Homebrew cask is disabled since 1 September 2026. The macOS page explains how to open it anyway and how you can help get it signed (#1542). - Linux: distribution packages are signed by the distributions that build them. The AppImage is not signed by a certificate authority; like every release asset it has a detached GPG signature.
Every file on the
releases page,
on every platform, comes with a detached GPG signature
(.asc) by the maintainer; see
Security for the key and how to check it.
Team roles
-
Committers and reviewers: the
IJHack members with write
access to the QtPass repository. Every change reaches
mainthrough a pull request with signed commits that has passed CI and automated review; committers merge their own changes, and contributions from outside the team are reviewed by a committer before they are merged. - Approvers: Anne Jan Brouwer. Every signing request waits for manual approval in SignPath before anything is signed.
The IJHack organization on GitHub requires two-factor authentication for every member, and SignPath accounts use multi-factor authentication as well.
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. QtPass has no network code of its own; git talks to the remote you configure. Read the full privacy policy.
Checking a signature
In Explorer, right-click the installer, choose Properties → Digital Signatures, and check that the signer is SignPath Foundation. In PowerShell:
Get-AuthenticodeSignature .\qtpass-x.y.z.exe | Format-List
Report anything signed with this certificate that did not come from the QtPass releases page to [email protected].