Code signing policy

Every Mortar release is built from this project's public source by GitHub Actions, and every file it ships can be checked against a signature or a published checksum.

What is signed

ArtifactSignatureChecked by
Every release fileSHA256SUMS, signed with the Mortar packages OpenPGP key, and a GitHub build provenance attestationYou: gpg --verify, sha256sum --check, gh attestation verify
In-app updatesed25519 signature for each file in the release's manifest.jsonMortar, before it installs an update
apt, dnf and pacman repositoriesRepository metadata and each .rpm and Arch package, signed with the Mortar packages keyapt, dnf and pacman
Scoop and HomebrewSHA-256 of each download pinned in the manifest, taken from the signed SHA256SUMSScoop and Homebrew
Firefox extensionSigned by MozillaFirefox

The Mortar packages key is 3283 6046 06CA E229 5D47 6F98 83BC 8751 EE6F 773D, published at mortar.rethunk.tech/packages, in the repository and on keyserver.ubuntu.com. The private keys live only in the repository's GitHub Actions secrets.

Windows code signing

Mortar has applied to the SignPath Foundation's free code signing program for open-source projects. Once approved, Windows installers and executables are signed through SignPath.io with a certificate issued to SignPath Foundation, and each release is approved for signing by the approver below.

Who builds and approves releases

Releases are built only from tags in Rethunk-Tech/mortar by its release workflow, published as a draft, verified, and only then made public. Published releases are immutable. Accounts with write access use multi-factor authentication.

Privacy

What Mortar sends over the network, and when, is in the privacy policy. Mortar collects no telemetry.

Report a problem

A signature that does not verify, or a file you suspect was tampered with: [email protected], or GitHub's private vulnerability reporting on the repository.