Code signing policy¶
Editions: OSS, Cloud, Enterprise. Unless stated otherwise, everything on this page ships in OSS.
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
Signed release provenance¶
Since v0.15.0, GitHub release assets carry Sigstore build provenance generated with the Release workflow's GitHub OIDC identity. This covers all attached CLI binaries, Python packages, Helm charts, installers, Compose configuration, SBOMs, and the checksum manifest. See release verification for verification commands and coverage limits.
Windows Authenticode¶
Windows CLI release binaries published on GitHub Releases:
preloop-windows-amd64.exepreloop-windows-arm64.exe
These artifacts are built by GitHub Actions from this repository on version
tags (v*). When SignPath credentials and policy are configured, they are
submitted for Authenticode signing before attachment to the release. Otherwise
the workflow warns and publishes them without Authenticode signatures. macOS
and Linux binaries use the Sigstore provenance above, not Authenticode.
See also windows-code-signing.md for CI wiring and maintainer setup.
Team roles¶
Per SignPath Foundation conditions for Open Source projects:
| Role | Members |
|---|---|
| Authors | preloop organization members trusted to modify source in this repository |
| Reviewers | preloop organization members who review pull requests |
| Approvers | preloop organization owners who approve SignPath signing requests |
Privacy policy¶
CLI and self-hosted instance telemetry (optional, opt-out) is documented in
SECURITY.md ยง Telemetry. Set
PRELOOP_DISABLE_TELEMETRY=true to disable it.
For Preloop Cloud / hosted services, see https://preloop.ai/privacy.