Skip to content
Discussion options

You must be logged in to vote

v1.1.0 is now built entirely by GitHub Actions on public runners: every asset on the
release page comes from the
tagged workflow run (33353741532),
with the exact toolchain in the run log and each file's SHA-256 in checksums.txt.

That closes the commitment made in this thread after the Defender false positive
(Microsoft submission cd681984, later cleared 0/69 on VirusTotal): a binary anyone
can rebuild from a public tag is a claim a reporter can verify, and a binary built on
one laptop is not. If Defender ever flags an asset again, the Actions run for its tag
is the reference to submit.

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by skymanbp
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #2 on August 28, 2026 02:56.