Skip to content

Conversation

@shijie-oai
Copy link
Collaborator

@shijie-oai shijie-oai commented Nov 14, 2025

Summary

  • install Sigstore cosign during Linux release builds and produce .sigstore bundles for each binary

  • run Azure Trusted Signing for Windows targets and publish the resulting signatures alongside the artifacts

  • document the new signing requirements in the release management guide

  • Swap out AZURE_TRUSTED_SIGNING_CLIENT_ID for release flow.

@shijie-oai shijie-oai force-pushed the codex/add-code-signing-support-for-linux-and-windows branch 2 times, most recently from a83b76a to 065fbe9 Compare November 21, 2025 17:43
@shijie-oai shijie-oai force-pushed the codex/add-code-signing-support-for-linux-and-windows branch from dac1fb7 to 8fe206d Compare December 5, 2025 23:01
@shijie-oai shijie-oai closed this Dec 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants