Some antivirus engines heuristically flag the self-signed, low-prevalence Windows installer (issue #198). Give downloaders a way to confirm assets are exactly what CI built: a checksum manifest plus signed SLSA provenance verifiable via gh attestation verify, with triage + code-signing policy docs linked from the README and release notes. |
||
|---|---|---|
| .. | ||
| antivirus-false-positives.md | ||
| code-signing-policy.md | ||
| p2p-collaboration-threat-model.md | ||