Code signing policy
How releases are built and signed.
Every Type3arabi installer is built from the public source code by an automated workflow on GitHub’s own servers, and a person approves each release before it is published.
سياسة توقيع البرنامج
كيف تُبنى الإصدارات وتُوقَّع.
كل ملف تثبيت لـ«اكتب عربي» يُبنى من الشيفرة المصدرية المنشورة، بعملية آلية على خوادم GitHub نفسها، ويوافق شخص على كل إصدار قبل نشره.
Last updated 25 September 2026 آخر تحديث: ٢٥ سبتمبر ٢٠٢٦
Current status: not signed yet
Type3arabi’s installers are not code-signed yet, so Windows shows “Unknown publisher”. We intend to apply to SignPath Foundation, which provides free code signing to open-source projects; the project has not been accepted yet. Until releases are signed, check each download against the SHA-256 published with the release (below).
If SignPath Foundation accepts the project, this page will say so, and releases will carry a signature with a certificate issued to SignPath Foundation.
الوضع الحالي: غير موقّع بعد
ملفات تثبيت «اكتب عربي» غير موقّعة رقمياً بعد، لذلك يعرض ويندوز «ناشر غير معروف». ننوي التقدّم إلى مؤسسة SignPath التي توفّر التوقيع مجاناً للمشاريع مفتوحة المصدر، ولم يُقبل المشروع بعد. وإلى أن تُوقَّع الإصدارات، تحقّق من كل ملف تنزّله ببصمة SHA-256 المنشورة مع الإصدار (أدناه).
إن قبلت مؤسسة SignPath المشروع فستذكر هذه الصفحة ذلك، وستحمل الإصدارات توقيعاً بشهادة صادرة لمؤسسة SignPath.
Team and roles
- Committers and reviewers
- Hassan Obaida (@ArabSeven). Changes proposed by anyone else (pull requests) are reviewed before they are merged.
- Approvers
- Hassan Obaida (@ArabSeven). Every signing request is approved by hand, one release at a time.
Team members use multi-factor authentication for the source repository and for code signing.
الفريق والأدوار
- أصحاب صلاحية التعديل والمراجعة
- حسن عبيدة (@ArabSeven). أي تعديل يقترحه غيره (طلب دمج) يُراجَع قبل دمجه.
- أصحاب صلاحية الموافقة
- حسن عبيدة (@ArabSeven). كل طلب توقيع يُوافَق عليه يدوياً، إصداراً بإصدار.
يستخدم أعضاء الفريق التحقّق متعدد العوامل للوصول إلى المستودع وإلى التوقيع.
What is signed
- Only Type3arabi’s own files, built from its own source code: the keyboard (
t3a_tip.dll, 64- and 32-bit), the sign-in helper (t3a-hotkey.exe),Type3arabi Settings.exe, and the installer (.msi) that contains them. - The installer also contains two small setup components of the WiX Toolset, the open-source tool that builds it. They keep the signature of their own authors (WiX Toolset, .NET Foundation) and are never signed by us.
- The language model (
type3arabi.dat) is a data file, not a program; its sources are listed in DATASETS.md and its exact SHA-256 is recorded in the repository.
ما يُوقَّع
- ملفات «اكتب عربي» نفسها فقط، المبنية من شيفرته المصدرية: لوحة المفاتيح (
t3a_tip.dllبنسختي ٦٤ و٣٢ بت)، والبرنامج المساعد عند تسجيل الدخول (t3a-hotkey.exe)، وType3arabi Settings.exe، وملف التثبيت (.msi) الذي يضمّها. - يحوي ملف التثبيت أيضاً مكوّنين صغيرين للتثبيت من WiX Toolset، الأداة مفتوحة المصدر التي تبنيه؛ يحتفظان بتوقيع مؤلفيهما (WiX Toolset, .NET Foundation) ولا نوقّعهما نحن أبداً.
- النموذج اللغوي (
type3arabi.dat) ملف بيانات وليس برنامجاً؛ مصادره مذكورة في DATASETS.md وبصمته SHA-256 الدقيقة مسجّلة في المستودع.
How a release is made
- A version tag is pushed to the public repository.
- GitHub’s hosted Windows runners build every binary and the installer from that tag (the release workflow is part of the source code).
- Automated checks verify the installer’s contents, version information and install behaviour.
- Once signing is in place, the unsigned build goes to the signing service, an approver approves it, and the signatures are checked again.
- A draft release with the installer and its SHA-256 checksums is created; the maintainer publishes it.
كيف يُصنع الإصدار
- يُدفع وسم الإصدار إلى المستودع العام.
- تبني أجهزة GitHub المستضافة لويندوز كل الملفات وملف التثبيت من ذلك الوسم (وسير عمل الإصدار جزء من الشيفرة المصدرية).
- تتحقّق فحوص آلية من محتوى ملف التثبيت ومعلومات الإصدار وسلوك التثبيت.
- عند توفّر التوقيع: يذهب البناء غير الموقّع إلى خدمة التوقيع، فيوافق عليه صاحب الصلاحية، ثم تُفحص التواقيع مجدداً.
- يُنشأ إصدار مسوَّدة يحوي ملف التثبيت وبصمات SHA-256، وينشره المطوّر.
Verify your download
Compare the SHA-256 of the file with the one on the release page:
Get-FileHash .\Type3arabi-x64.msi -Algorithm SHA256
For signed releases, also check the signature (Status must be Valid):
Get-AuthenticodeSignature .\Type3arabi-x64.msi | Format-List Status, SignerCertificate
تحقّق من الملف الذي نزّلته
قارن بصمة SHA-256 للملف بالبصمة المنشورة في صفحة الإصدار:
Get-FileHash .\Type3arabi-x64.msi -Algorithm SHA256
وفي الإصدارات الموقّعة تحقّق من التوقيع أيضاً (يجب أن تكون الحالة Valid):
Get-AuthenticodeSignature .\Type3arabi-x64.msi | Format-List Status, SignerCertificate
Privacy
This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. Details: privacy policy.
Report a problem
If you believe a Type3arabi file is not what it claims to be, open an issue on GitHub or contact the maintainer through linktr.ee/hassanobaida.
الخصوصية
لا ينقل هذا البرنامج أي معلومات إلى أنظمة أخرى على الشبكة إلا بطلب صريح من المستخدم أو ممّن يثبّته أو يشغّله. التفاصيل في سياسة الخصوصية.
الإبلاغ عن مشكلة
إن ظننت أن ملفاً باسم «اكتب عربي» ليس ما يدّعيه، فافتح بلاغاً على GitHub أو تواصل مع المطوّر عبر linktr.ee/hassanobaida.