Code signing policy
Code signing policy
本页说明 Agent Pi DSH 安装包的签名与完整性校验政策。
- 3.5.3 当前公开构件未签名或公证,Windows SmartScreen 或其他平台安全机制可能提示风险。
- GitHub Release 会提供构件摘要或校验文件(如有);Windows 用户应在安装前核对官网显示的 SHA256。
- 后续正式签名构件只通过受控发布流水线生成,签名密钥由签名服务托管,项目维护者不直接接触私钥。
- 签名状态与摘要以 GitHub Release 中对应构件的信息为准。
如有签名相关问题,请通过参赛测试通知中的项目联系人反馈。
This page states the installer signing and integrity policy of Agent Pi DSH.
- The current 3.5.3 public artifacts are unsigned or unnotarized, so Windows SmartScreen or another platform's security checks may display a warning.
- GitHub Release provides an artifact digest or checksum file when available; Windows users should verify the SHA256 shown on the website before installation.
- Future signed artifacts will be produced only through a controlled release pipeline; signing keys remain with the signing service and are not directly accessible to maintainers.
- The corresponding GitHub Release asset information is authoritative for signing status and digests.
For signing questions, use the project contact included with the competition test notice.