Skip to content

Release notes claim 'Installer signature: NotSigned' for an installer that is signed #180

Description

@dfattal

preview-0.1.22's generated notes claimed:

Installer signature: **NotSigned**

The installer is signed. Checked the PE certificate table
(IMAGE_DIRECTORY_ENTRY_SECURITY, data-directory index 4) directly on both published assets:

release security dir offset size verdict
preview-0.1.21 205706696 10576 SIGNED
preview-0.1.22 205706704 10576 SIGNED

So this is a reporting bug, not a signing failure — but it is the damaging direction: a
correctly-signed build that publicly advertises itself as unsigned invites users to distrust
it, and would mask a real signing regression by making "NotSigned" look like business as
usual.

Likely cause

release.sh computes SIG via Get-AuthenticodeSignature before gh release create,
so in the pipeline the value reflects whatever the file was at that moment. If the staged
publish runs the notes generation against the pre-signing artifact (or against a path
PowerShell cannot resolve — the MSYS /c/... case the script already documents at the
cygpath -w line), it reports NotSigned for a file that is signed by the time it is
uploaded.

Suggested fix

Derive the signature line from the artifact actually being uploaded, after signing, and
fail loudly rather than silently embedding a wrong claim — an Unknown/NotSigned result on
a release build should be an error, not a note. A cheap cross-check that needs no Windows: a
signed PE has a non-zero size in data directory index 4.

Notes for 0.1.22 have been corrected by hand; the underlying generator has not been changed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions