Code signing policy
Every Mortar release is built from this project's public source by GitHub Actions, and every file it ships can be checked against a signature or a published checksum.
What is signed
| Artifact | Signature | Checked by |
|---|---|---|
| Every release file | SHA256SUMS, signed with the Mortar packages OpenPGP key, and a GitHub build provenance attestation | You: gpg --verify, sha256sum --check, gh attestation verify |
| In-app updates | ed25519 signature for each file in the release's manifest.json | Mortar, before it installs an update |
| apt, dnf and pacman repositories | Repository metadata and each .rpm and Arch package, signed with the Mortar packages key | apt, dnf and pacman |
| Scoop and Homebrew | SHA-256 of each download pinned in the manifest, taken from the signed SHA256SUMS | Scoop and Homebrew |
| Firefox extension | Signed by Mozilla | Firefox |
The Mortar packages key is 3283 6046 06CA E229 5D47 6F98 83BC 8751 EE6F 773D, published at
mortar.rethunk.tech/packages, in the
repository
and on keyserver.ubuntu.com. The private keys live only in the repository's GitHub Actions secrets.
Windows code signing
Mortar has applied to the SignPath Foundation's free code signing program for open-source projects. Once approved, Windows installers and executables are signed through SignPath.io with a certificate issued to SignPath Foundation, and each release is approved for signing by the approver below.
Who builds and approves releases
- Authors (commit without further review): Damon Blais (@Albinogeek), the author of every commit.
- Reviewers (review every change from anyone else): Damon Blais (@Albinogeek).
- Approvers (approve each release before it is signed and published): Damon Blais (@Albinogeek).
Releases are built only from tags in Rethunk-Tech/mortar by its release workflow, published as a draft, verified, and only then made public. Published releases are immutable. Accounts with write access use multi-factor authentication.
Privacy
What Mortar sends over the network, and when, is in the privacy policy. Mortar collects no telemetry.
Report a problem
A signature that does not verify, or a file you suspect was tampered with: [email protected], or GitHub's private vulnerability reporting on the repository.