Code signing policy

Promptline's Windows releases are not code-signed yet.

Promptline means to sign its Windows installers through the free programme SignPath Foundation runs for open-source projects, on the SignPath.io signing service. This page is the policy those signed releases will follow: what is signed, who approves it, and what the app sends over the network.

Status. Releases so far are unsigned. SignPath Foundation didn't accept the project's first application, in September 2026; the project will apply again, and this line will name the first signed release.

What is signed

Every Windows release carries two installers built from this repository's source: Promptline_X.Y.Z_x64-setup.exe (NSIS) and Promptline_X.Y.Z_x64_en-US.msi. A signed release is built by GitHub Actions from the release's version tag, on GitHub's own Windows runners, never on a personal machine; the unsigned releases so far were built on the maintainer's machine. In a signed release the app itself, promptline.exe, is signed before it is packed into each installer, and then each installer is signed, so the download and the program it installs carry the same signature.

The certificate is issued to SignPath Foundation, so Windows names SignPath Foundation as the publisher. Its private key stays in SignPath's hardware security module; this project never holds it. Only binaries built from Promptline's own source are signed; files the installer builder takes from other open-source projects (NSIS's plug-ins, for example) may be included unsigned.

Separately, each installer carries an updater signature made with the maintainer's own key, which stays on the maintainer's machine and never goes to GitHub. An installed copy of Promptline installs an update only if that signature matches the key built into it.

How a release is signed

  1. A version tag on master starts the build in GitHub Actions.
  2. The build sends promptline.exe to SignPath, and the maintainer approves the signing request on SignPath.
  3. The installers are built around the signed program and sent to SignPath, and the maintainer approves that request too.
  4. The maintainer checks the signatures, adds the updater signature, and publishes the release on GitHub.

Nothing is signed without a person approving the request on SignPath.

Team roles

Promptline has one maintainer, who holds every role.

Committers and reviewers
Alpaslan Bek (@bekalpaslan) writes and reviews every change. Outside contributions arrive as pull requests and are merged only after that review.
Approvers
Alpaslan Bek (@bekalpaslan) approves each signing request on SignPath.

Team members must use multi-factor authentication on GitHub and on SignPath.

Privacy

No telemetry. One update check, off in a click. At startup and once a day Promptline fetches one small file, https://promptline.cc/latest.json, to see whether a newer release exists. The address is fixed and the same for everyone; the request carries nothing about you (no version, no ID, no usage). Like any web request it reaches GitHub Pages, which hosts promptline.cc and logs IP addresses, and it names the updater library as its user agent. If you accept an update, the installer downloads from GitHub Releases and is installed only if its signature matches the key built into the app. Turn the check off under Settings → About; Check for updates there still works by hand. Nothing else leaves your machine except what you paste.

Promptline collects no user data and transfers none to other systems. The update check sends nothing about you, so the installer has no privacy page or opt-out of its own; Settings → About turns the check off. Your prompts, packs and settings are files on your own machine, and so is the log (promptline.log), which leaves it only if you attach it to a bug report.

This site's own privacy note is at the foot of the home page.

Questions and reports

Report a security problem through GitHub's private vulnerability reporting or to security@promptline.cc (SECURITY.md). Anything else goes to the issue tracker.