Status: releases are not code-signed yet. This page describes how signed
releases of HelixBoot.exe are to be made, and what the program does on your
PC and on the network. Until a release is signed, check a download with its
SHA256SUMS file and build attestation (how).
Free code signing provided by SignPath.io, certificate by SignPath Foundation.
- Only
HelixBoot.exeis signed, and only as built by this repository's own GitHub Actions workflow (windows.yml) from a tagged commit onmain. Nothing built on anyone's own PC is signed. - The build is tested before it is signed: the workflow runs the real
.exethrough an install, an update, a stick check and the Look window. - Every release is approved by hand before it is signed.
- The
.execarries its product name and version (Properties > Details); the version matcheshelix --versionand the release's tag.
| Role | Who |
|---|---|
| Committers and reviewers | Commanderx-code |
| Approvers | Commanderx-code |
Changes from anyone else come in as pull requests and are reviewed before they are merged. Accounts with access to the repository or to signing use multi-factor authentication.
Helix Boot has no accounts, no telemetry and no analytics. It sends nothing to this project or to its maintainer, and it collects no information about you or your PC.
It does make ordinary web requests to the publishers of the tools it puts on a stick, and to nobody else:
- When the app starts, it asks GitHub, SourceForge and the tools' own
download sites for the latest version number of each tool, to tell you which
have newer versions. It does this at most once every 6 hours. To turn it off,
put
check_for_updates = falseunder[settings]inlocal.toml, next to the.exe. - When you press Install or Update with the internet chosen, it downloads the tools and their checksums from those same sites. With a pack chosen it downloads nothing.
Like any download, those requests show the site your IP address. They carry no
identifier of yours. If you set a GITHUB_TOKEN yourself, it is sent to
api.github.com only.
- Install erases the USB stick you pick, after you type its disk number to confirm. Only USB and SD disks are offered, never the disk Windows runs from.
- Update, Look… and Check stick write only to the stick you pick. Update first shows what it will copy, remove and keep, and asks.
- Downloads are kept in
%LOCALAPPDATA%\HelixBoot. A log, yourlocal.tomland yourbyofolder sit next to the.exe. - It installs nothing into Windows and changes no Windows settings.
Delete HelixBoot.exe and the files next to it, and the folder
%LOCALAPPDATA%\HelixBoot. Nothing else is left behind.