Status: JBrowser is set up to be signed through SignPath Foundation's free code signing for open-source software, and is applying for it. Until it is approved, releases are not code-signed, and Windows SmartScreen may show "Windows protected your PC" for a downloaded installer. The download page explains how to install without the warning. This policy applies from the first signed release.
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
What is signed
JBrowser.exe, the browser itself, andJBrowser-Setup-<version>.exe, its installer, for every release published on GitHub Releases.- Nothing else: JBrowser signs only programs built from its own source code. The Qt, Python and Chromium files inside JBrowser are signed by their own publishers or not at all.
How signed builds are made
- Every signed release is built from its tagged source code by the release-build workflow on GitHub's own (GitHub-hosted) Windows machines, never on a personal computer.
- The workflow sends the built programs to SignPath, which checks that they came from this repository and this workflow, and that their product name (JBrowser) and version match the release.
- Each signing request is approved by hand by an approver before anything is signed.
- Installed copies of JBrowser that are signed accept an update only if it is signed by the same publisher, in addition to checking its SHA-256 fingerprint.
Team roles
| Role | Who |
|---|---|
| Committers and reviewers | The JBrowser Team (JB, Miles and Tom), through the team's GitHub account; see the contributors. Changes from anyone else are reviewed by a team member before they are merged. |
| Approvers | The JBrowser Team's maintainers. An approver approves every signing request. |
Team members use multi-factor authentication for GitHub and SignPath.
Privacy
JBrowser sends nothing about you or your browsing to the JBrowser team. The connections it makes by itself (update checks, protection lists, secure DNS and search suggestions) are listed in the privacy policy.
Reporting a problem
If you believe a signed JBrowser program behaves maliciously, or was signed without following this policy, report it privately as described in the security policy.