Code signing policy
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
Current signing status
The latest public release, winTerm 1.4.3, is not Authenticode-signed. The SignPath Foundation certificate has not been issued for this project yet, and no signed winTerm binaries exist. Windows may show an Unknown Publisher or SmartScreen warning for the current Setup EXE. Verify every download against SHA256SUMS.txt from the same official GitHub Release. This page will state when releases are actually signed.
Team and roles
winTerm is maintained under the public identity HelloThisWorld.
- Authors and committers: HelloThisWorld
- Reviewers: HelloThisWorld
- Approvers: HelloThisWorld
Changes from external contributors are accepted only through pull requests reviewed by a maintainer. Review explicitly covers source code, CI configuration, GitHub Actions workflows, build and packaging scripts, dependency downloads, and any signing-related configuration.
Build provenance
Official winTerm releases are built from the public winTerm repository by GitHub Actions on GitHub-hosted runners, starting from an immutable release tag that must match the repository version metadata. Release assets are published with SHA-256 checksums, SBOMs, and GitHub artifact attestations, and are re-downloaded and verified before the release is made public.
Release signing approval
Every release signing request requires manual approval by an approver listed above. No signing happens automatically, and no artifact outside the official release pipeline is signed.
Privacy
See the winTerm privacy policy on this site and the canonical PRIVACY.md in the repository. winTerm does not collect command text, terminal output, clipboard content, workspace contents, working-directory paths, or usage analytics.
Installation and removal
The installation guide documents exactly what the Setup EXE changes on a system, including shortcuts, the winterm.exe App Paths command, and optional File Explorer integration. The uninstall guide documents standard removal, which does not touch Microsoft Windows Terminal, wt.exe, WSL, PowerShell profiles, or global fonts.
Canonical policy
The repository copy of this policy lives in the winTerm README and the repository policy documents. If this page and the repository ever disagree, the repository is authoritative.