Code signing policy
Desktop builds of Stoop are signed by get stoop LLC. This page says what is signed, who holds the keys, and how to check a build.
What is signed
- macOS: the application bundle and installer, signed with a Developer ID certificate issued to get stoop LLC and notarized by Apple.
- Windows: the installer and executable, signed with a code-signing certificate issued to get stoop LLC.
- Linux and the server: release archives ship with a SHA-256 checksum file beside them. Check the archive against it before use.
Who signs
Signing keys are held by get stoop LLC and used only in the release pipeline for builds published under github.com/getstoop. No third party signs on our behalf. If a key is ever compromised, the certificate is revoked, the affected releases are withdrawn from the release index, and a notice is posted here and in the release notes.
Checking a build
On macOS, the app's signature names get stoop LLC in the system's verification dialog and in codesign -dv. On Windows, the file's properties show a digital signature from get stoop LLC. A build that shows a different name, or no signature, did not come from us.
Reporting a problem
A build that fails verification, or a signed build you did not get from this site or the GitHub releases page, is a security report. See the security policy.