Skip to content

Code signing

Release builds are not code-signed. The MSI installers, the add-in assemblies and the updater are built by the release workflow in this repository and published without an Authenticode signature.

Verify downloads

Every release publishes SHA256SUMS.txt and a build provenance attestation for its assets. See Verify downloads for the commands. install.ps1 and the add-in updater check SHA256SUMS.txt before they install anything.

Revit's unsigned add-in prompt

Revit asks whether to load an unsigned add-in the first time it loads the DLL, and again whenever the DLL content or its path changes. Choose Always Load and close Revit normally; Revit keeps the decision only after a graceful exit. Each automatic update therefore causes one prompt at the next Revit start.

Organizations that deploy their own code-signing certificate can sign the installed DLLs with install.ps1 -SignThumbprint <thumbprint>; see transport.

Plans

I am looking for another certificate for open source builds; this page will list what is signed and how once that is in place.