We looked into getting DiapDealer a Windows signing certificate (for money) but individual signing certificates (not institutional) would not prevent the issue of various anti-virus programs claiming we are "potential malware" for each new release based only on download counts.
So there was no point. Both winget and Chocolatey do their own testing so it makes sense for people to use them if they are concerned and actually believe the download count nonsense.
For example, Sigil has a long history of making perfectly safe releases with Windows download counts of approximately 75k to 80k downloads for each main release which should be reputation enough but is completely ignored by the third party crap anti-virus checkers.
|