Effective 5 October 2026

Code Signing Policy

This document outlines the code signing policy for TMPlayer binaries, detailing how we ensure the integrity and authenticity of our releases.

Build Process

All TMPlayer releases are built exclusively via automated Continuous Integration (CI) pipelines on GitHub Actions. No releases are built manually on developer machines. The CI pipeline pulls the source code directly from the repository, builds the artifacts, and prepares them for signing.

Code Signing

To ensure that users receive untampered binaries, we digitally sign our Windows releases using a certificate provided by the SignPath Foundation. The signing process is integrated into our automated CI pipeline and is only triggered for official release tags.

Android releases are signed with our own secure keystore, managed via GitHub Secrets.

Access Control

Only authorized maintainers (currently dracu-lah) have write access to the TMPlayer repository and the ability to push tags that trigger the release and signing pipeline. Branch protection rules are in place for the main branch to ensure all changes go through proper review.

Verification

Users can verify the signature of our Windows binaries by checking the digital signature properties in Windows Explorer. The certificate should be issued to our open source project via SignPath Foundation.

Questions

Email hello@tmplayer.org with a question about signing. For what the app and this website collect, see the privacy page. Material changes to this page will update the effective date above.