Skip to content

Decide the code signing route: reapply to the SignPath Foundation later, or pay #358

Description

@zcsizmadia

Split out of #77, which had this as a cross-cutting line item. It is not an engineering task and it blocks several that are, so it deserves its own place.

Where things stand

The SignPath Foundation application — the free programme for open source — was declined for now. It is for projects with an established user base, and Skrog does not have one yet. They invited a reapplication as visibility grows.

Binaries are unsigned, SmartScreen warns on first run, and nobody has promised a date.

The two routes

cost timing catch
Reapply to the Foundation free when visibility grows gated on the very thing signing would help with
Buy a certificate money, recurring any time none beyond the money

The circularity, which is the real problem

free route  ->  needs adoption
adoption    ->  driven fastest by winget
winget      ->  wants a signed installer (an unsigned one asking for
                elevation is a worse first impression than a zip)
signing     ->  needs a certificate

And SmartScreen reputation only begins accruing after signing, so the warning persists for a while even once signed. Paying is the only move that breaks the loop without waiting on anyone else. That does not make it right — it makes it the one that does not depend on a third party's judgement of our popularity.

The part that is not about money

This is the bit worth deciding deliberately.

The Foundation issues the certificate to the project, and requires an OSI-approved licence with no commercial dual-licensing, for any component. A future paid tier would end eligibility. They can also pause or revoke, immediately or retroactively, over a Code of Conduct violation.

A purchased certificate costs money, but nobody can withdraw it over a licence change or a disagreement.

So the free route keeps a door open that the paid route closes, and vice versa. If a paid tier is ever plausible — ROADMAP lists a priority-support tier as a sustainability idea — accepting a Foundation certificate later is the thing that forecloses it.

What a decision unblocks

What is already true regardless

Every release carries SLSA build provenance and a cosign-signed SHA256SUMS, which answer "was this built by that workflow, from that commit" — a question an Authenticode signature does not answer. Not a substitute for signing, and documented as such. See docs/code-signing.md, which also keeps the roles and CI-only signing rules ready for whichever route wins.

Options, for the record

  1. Wait and reapply. Free, no decision now, indefinite.
  2. Pay. Unblocks everything immediately; costs money; keeps a commercial option open later.
  3. Wait, but push visibility deliberately — the upstream posts on microsoft/WSL, docs SEO, a Show HN — and reapply at a threshold decided in advance rather than "when it feels like enough".

Option 3 is the only one that treats the circularity as a plan rather than a trap; it is also the slowest.

Activity

  1. zcsizmadia commented on Sep 16, 2026

    @zcsizmadia
    CollaboratorAuthor

    Correction to the circularity argument in the issue body: the loop is not closed.

    I wrote that the free route needs adoption, adoption needs winget, and winget needs a signed installer. The last link is false.

    winget requires signing only for installers that elevate (MSI / setup EXE). Its portable type does not — verified against two unsigned GitHub-release zips shipping on winget today:

    > winget show BurntSushi.ripgrep.MSVC
      Installer Type: portable (zip)
    > winget show junegunn.fzf
      Installer Type: portable (zip)
    

    Skrog already publishes that artifact shape. Details and the manifest in #77.

    What that changes here

    The decision is no longer free-but-blocked versus paid-and-now. Option 3 — grow visibility deliberately, then reapply — is now the cheap one rather than the slow one, because its main lever was reachable all along:

    1. Wait and reapply free, indefinite, passive
    2. Pay unblocks the MSI immediately; keeps a future commercial tier open
    3. Push visibility, then reapply now costs nothing but effort — winget, scoop, the upstream posts, docs SEO

    Option 2 still buys one thing option 3 cannot: the MSI and Intune deployment, which genuinely does need a signed elevating installer. If enterprise deployment matters soon, that is the argument for paying. If it does not, option 3 gets the SmartScreen problem shrinking without spending anything, and leaves the licence question open.

    Unchanged

    Everything in the issue about what the routes cost beyond money still stands, and it is still the part worth deciding on: the Foundation issues the certificate to the project, forbids commercial dual-licensing of any component, and can revoke; a purchased certificate cannot be withdrawn over a licence change. Each closes a door the other keeps open.

    Also unchanged: SmartScreen warns on skrog.exe regardless of how it was obtained. winget changes distribution, not trust.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions