MushrifLoop

Code signing policy

How the releases are built and signed.

This page says who signs MushrifLoop's Windows files, how a release gets from the public source to a signed download, who may approve a signature, and what the app sends over the network.

Not signed yet

Signing through SignPath Foundation is being set up. Releases up to and including 1.7.0 are not signed, and Windows shows them as coming from an unknown publisher. The first signed release will say so in its notes, and this note will go.

Signing

Who signs the files.

Free code signing provided by SignPath.io, certificate by SignPath Foundation.

Windows shows the publisher of a signed release as SignPath Foundation. The signature says that the file was built from this project's public source code and has not been changed since. The certificate's private key is held by SignPath in a hardware security module; the project never has it.

Building

Built in public, approved by hand.

  1. Every release is built by GitHub Actions, on runners hosted by GitHub, from the public repository github.com/hqudsi/mushrifloop at the release's tag. A file built anywhere else is never signed.
  2. The build signs the app's own program and both downloads: the installer and the portable file.
  3. Each signing request waits for an approver, who checks that it comes from a release of this repository before approving it.
  4. Each release lists the SHA-256 of its files, so any download can be checked against it.

Team

Who may change the code and approve a signature.

MushrifLoop has one maintainer. Anyone else's change comes as a pull request, and nothing from outside the team is merged without that check. Everyone in these roles uses multi-factor authentication for GitHub and for SignPath.

  • CommittersMay commit to the repository: Hani Qudsi.
  • ReviewersCheck every change from outside the team before it is merged: Hani Qudsi.
  • ApproversApprove each signing request: Hani Qudsi.

Privacy

What the app sends, and when.

MushrifLoop has no account, server, analytics or telemetry of its own. Your tasks, settings and logs stay in %APPDATA%\MushrifLoop on your computer. The app sends something over the network only in these cases.

  • New MushrifLoop versions At start and once a day, while Check for new MushrifLoop versions is on (Settings → General; on by default), the app asks GitHub (api.github.com) for this repository's latest release. The request carries the app's name and version, and nothing else. Switch it off and nothing is asked on its own; Check now asks only when you press it.
  • A newer Claude Code Only when you press Check for a newer Claude Code in Settings: the app asks the npm registry (registry.npmjs.org) for the newest published Claude Code version. Nothing about you or your tasks is sent.
  • Updating Claude Code Only when you press Update Claude Code: the app runs Claude Code's own claude update.
  • Claude Code itself The app runs the Claude Code installed on your computer, signed in with your own account. When a task runs, and when the app asks which account is signed in or how much usage is left, Claude Code talks to Anthropic as it does when you use it directly, and Anthropic's privacy policy applies. MushrifLoop never calls the Anthropic API itself.
  • Links A link in the app opens in your browser, and only when you click it.

GitHub and npm see these requests as any website sees a visit, with your IP address; their own privacy statements apply (GitHub, npm).

Uninstall

Removing it.

The installer adds MushrifLoop to Windows' Installed apps, and it is removed from there like any other app. The uninstaller asks whether to delete your tasks and settings as well. That box starts unticked, so by default they stay. The portable file installs nothing: delete it, and it is gone.

Questions about this policy go to the project's issues; security problems, as its security policy says.