Code signing policy

Desktop builds of Stoop are signed by get stoop LLC. This page says what is signed, who holds the keys, and how to check a build.

What is signed

Who signs

Signing keys are held by get stoop LLC and used only in the release pipeline for builds published under github.com/getstoop. No third party signs on our behalf. If a key is ever compromised, the certificate is revoked, the affected releases are withdrawn from the release index, and a notice is posted here and in the release notes.

Checking a build

On macOS, the app's signature names get stoop LLC in the system's verification dialog and in codesign -dv. On Windows, the file's properties show a digital signature from get stoop LLC. A build that shows a different name, or no signature, did not come from us.

Reporting a problem

A build that fails verification, or a signed build you did not get from this site or the GitHub releases page, is a security report. See the security policy.