SignPath Said No: Our Windows Builds Stay Unsigned for Now
A few days ago we told you here on the blog that we had applied to the SignPath Foundation's free open-source program for a code-signing certificate for our Windows installers. Now the answer has arrived — and it's a no. Since this devblog isn't just about celebrating wins but about honestly telling how a project like this really goes, this news belongs here too.
A quick reminder: what was this about? Unsigned Windows programs trigger the SmartScreen warning "Windows protected your PC" on first launch — from Windows' point of view, the installer comes from an "unknown publisher". A code-signing certificate makes that go away, but it costs money every year, which is a real hurdle for a family hobby project. The SignPath Foundation provides signing to open-source projects for free — that's exactly what we had applied for.
Why it didn't work out. The reasoning is fair: the Foundation program is aimed at projects that have already built up a certain level of public visibility and trust — GitHub stars, forks, external contributors, articles, discussions on Reddit or Stack Overflow. Our young project simply doesn't show enough of these signals yet. Explicitly included: this is no judgment on the quality of the work, and we're welcome to reapply once the project has gained broader recognition. That's exactly what we intend to do.
What this means for you. In practice: everything stays as it is. The SmartScreen warning on first launch will stay with us for a while. If you downloaded the game from our official GitHub page, you can confirm it with "More info → Run anyway". Please continue to download the game only from official sources — that's what the warning is there for, after all. We've updated our README, the security notices, and the code-signing policy to reflect the honest current state: not signed, application declined, next attempt planned.
So what now? The path is clear: the project needs to become more visible — more players, more stars, more voices from outside. We're working on that every day anyway; now there's one more reason. If you want to help, this is by the way the easiest contribution there is: a ⭐ on GitHub, showing the game to a friend, telling someone about it. Every bit of visibility brings us closer to the day the warning disappears. Until then: thanks for clicking "Run anyway" anyway. 🚀
Comments