Verity

Installers ship only after their signatures and checks pass

Verity does not currently publish Windows installers. This page explains what must happen before one becomes available.

Planned signing provider

Application pending: Free code signing provided by SignPath.io, certificate by SignPath Foundation.

This names the provider Verity is applying to use. It does not mean the application has been accepted or that any current build is signed. If approved, Windows will show SignPath Foundation as the publisher.

Who approves releases

logi-cmd is the current author, committer, reviewer, and signing approver. Contributions from other people must be reviewed before merge. Every signing request also needs a separate manual approval.

Release checks

  • The candidate is built from a public Verity tag on GitHub-hosted runners.
  • The signing service must connect the files to that workflow run and source tag.
  • The app executable and every published MSI or setup executable must pass Authenticode verification and include a trusted timestamp.
  • Installation, uninstallation, launch, and the Windows acceptance matrix must pass.
  • Unsigned installers are not published or linked from this website.
  • SHA-256 checksums, a release manifest, and an acceptance report ship with each installer release.

Privacy

Verity does not transfer repository source, paths, logs, command output, or complete receipts to another networked system. Network access happens only when the user explicitly asks for an action that needs it. Read the privacy page for details.

Last updated: August 16, 2026.