preview-0.1.22's generated notes claimed:
Installer signature: **NotSigned**
The installer is signed. Checked the PE certificate table
(IMAGE_DIRECTORY_ENTRY_SECURITY, data-directory index 4) directly on both published assets:
| release |
security dir offset |
size |
verdict |
preview-0.1.21 |
205706696 |
10576 |
SIGNED |
preview-0.1.22 |
205706704 |
10576 |
SIGNED |
So this is a reporting bug, not a signing failure — but it is the damaging direction: a
correctly-signed build that publicly advertises itself as unsigned invites users to distrust
it, and would mask a real signing regression by making "NotSigned" look like business as
usual.
Likely cause
release.sh computes SIG via Get-AuthenticodeSignature before gh release create,
so in the pipeline the value reflects whatever the file was at that moment. If the staged
publish runs the notes generation against the pre-signing artifact (or against a path
PowerShell cannot resolve — the MSYS /c/... case the script already documents at the
cygpath -w line), it reports NotSigned for a file that is signed by the time it is
uploaded.
Suggested fix
Derive the signature line from the artifact actually being uploaded, after signing, and
fail loudly rather than silently embedding a wrong claim — an Unknown/NotSigned result on
a release build should be an error, not a note. A cheap cross-check that needs no Windows: a
signed PE has a non-zero size in data directory index 4.
Notes for 0.1.22 have been corrected by hand; the underlying generator has not been changed.
preview-0.1.22's generated notes claimed:The installer is signed. Checked the PE certificate table
(
IMAGE_DIRECTORY_ENTRY_SECURITY, data-directory index 4) directly on both published assets:preview-0.1.21preview-0.1.22So this is a reporting bug, not a signing failure — but it is the damaging direction: a
correctly-signed build that publicly advertises itself as unsigned invites users to distrust
it, and would mask a real signing regression by making "NotSigned" look like business as
usual.
Likely cause
release.shcomputesSIGviaGet-AuthenticodeSignaturebeforegh release create,so in the pipeline the value reflects whatever the file was at that moment. If the staged
publish runs the notes generation against the pre-signing artifact (or against a path
PowerShell cannot resolve — the MSYS
/c/...case the script already documents at thecygpath -wline), it reportsNotSignedfor a file that is signed by the time it isuploaded.
Suggested fix
Derive the signature line from the artifact actually being uploaded, after signing, and
fail loudly rather than silently embedding a wrong claim — an
Unknown/NotSignedresult ona release build should be an error, not a note. A cheap cross-check that needs no Windows: a
signed PE has a non-zero size in data directory index 4.
Notes for
0.1.22have been corrected by hand; the underlying generator has not been changed.