1 hour ago · 9 min read1889 words · Tech · hide · 0 comments

The past year has been exciting for w64devkit, which like any software distribution is never complete. Peter0x44 joined as co-maintainer, and has pushed the project in good, new directions, with ideas I would never have considered. Many of his improvements have gone back upstream, and so you may benefit even if you don’t use w64devkit. I’d like to touch on the various odds and ends from the past year. Release security In April I announced that release packaging is now signed. Today all EXEs and DLLS in w64devkit are code-signed with my key. My signing key established a good reputation thanks to thousands of unique signatures observed on the order of ~100,000 hosts — a pleasant side effect from including ~300 binaries in a release. Users should have fewer problems these days with security software. MSYS2 has also adopted my signing tool, aas-sign, which is now included in w64devkit releases. Builds are now automated by GitHub Actions, triggered when I (and only I) push a new tag. That…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.