Automic VaultAutomic Vault

brew

Installer osslsigncode avec Homebrew, apt, dnf, MacPorts, Nix, zypper, scoop, winget

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de osslsigncode pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install osslsigncode

local Homebrew formula metadata

MacPortsvérifié · 94%
sudo port install osslsigncode

MacPorts ports tree · devel/osslsigncode/Portfile · Source: api.github.com

Linux

Debian aptvérifié · 92%
sudo apt install osslsigncode

Debian stable package indexes · osslsigncode · Source: deb.debian.org

Fedora dnfvérifié · 92%
sudo dnf install osslsigncode

Fedora Rawhide package metadata · osslsigncode · Source: dl.fedoraproject.org

Nixvérifié · 92%
nix profile install nixpkgs#osslsigncode

nixpkgs package indexes · pkgs/by-name/os/osslsigncode/package.nix · Source: api.github.com

openSUSE zyppervérifié · 92%
sudo zypper install osslsigncode

openSUSE Tumbleweed package metadata · osslsigncode · Source: download.opensuse.org

Windows

Scoopvérifié · 92%
scoop install main/osslsigncode

Scoop official bucket manifest trees · bucket/osslsigncode.json · Source: api.github.com

Windows Package Managervérifié · 92%
winget install --id MichalTrojnara.osslsigncode -e

Windows Package Manager source index · MichalTrojnara.osslsigncode · Source: cdn.winget.microsoft.com

aperçu

Résumé du paquet

OpenSSL based Authenticode signing for PE/MSI/Java CAB files

Commandes et alias

  • osslsigncode

historique

Historique du projet et usages

osslsigncode is an OpenSSL- and cURL-based command-line implementation of Authenticode signing, timestamping, verification, removal, and extraction for Windows-oriented file formats such as PE, CAB, CAT, MSI, APPX, and selected script files.

Historique du projet

The project was created to avoid depending on Microsoft's `signtool.exe` and Windows CryptoAPI when signing Windows binaries from Unix-like build environments. Its README explains the origin plainly: binaries could be built with Wine on Linux, but signing with signtool failed because the necessary Windows APIs were not fully implemented there.

The codebase records a longer authorship chain than the GitHub namespace suggests. The main C source includes copyright attribution for Per Allansson for 2005-2015 and Michal Trojnara for 2018-2023, while the maintained GitHub repository is under mtrojnar and uses CMake-based builds.

Historique d'adoption

osslsigncode filled a practical gap for cross-platform release engineering: sign Windows installers and executables from Linux or macOS CI systems using OpenSSL-compatible key material. Its packaging across Homebrew, Debian/Ubuntu, Fedora, MacPorts, Nix, Scoop, winget, and openSUSE reflects that it is used by build and security pipelines rather than by end-user desktop workflows.

Vendor documentation from DigiCert includes osslsigncode in third-party signing-tool instructions for PKCS#11 workflows, showing that certificate authorities and signing services treat it as a supported path for Authenticode operations outside Microsoft tooling.

Modes d'utilisation

A typical use signs a PE or MSI file with a certificate and private key, optionally adds an Authenticode or RFC 3161 timestamp, and verifies the resulting signature. The README also documents PKCS#12 containers, PKCS#11 engines and providers, Windows CNG engine use, CAB Java signing compatibility, and operations for extracting or removing signatures.

The tool is especially useful in CI/CD systems that build Windows artifacts on non-Windows hosts or store signing keys in HSM, token, PKCS#11, or provider-backed systems.

Pourquoi les passionnés de paquets s'y intéressent

osslsigncode is significant because it packages a Windows trust-format workflow in portable Unix-style form. It sits at the awkward intersection of OpenSSL, Windows Authenticode, timestamp authorities, hardware-backed keys, and reproducible release automation.

Related projects

  • Microsoft signtool.exe is the proprietary reference tool that osslsigncode partially replaces. OpenSSL, cURL, PKCS#11 engines/providers, and certificate-authority timestamp services are its operational dependencies and ecosystem neighbors.

posture de sécurité

Niveau de risque : vert

narrow executable package without higher-risk signals.

Classificateur de risque

risque vert · confiance faible · appliance

Pourquoi

  • narrow executable package without higher-risk signals

Signaux

  • metadata:no-higher-risk-signals

Comportement d'installation

  • Aucun hook post-install Homebrew n’est enregistré dans les métadonnées de formule.
  • Les métadonnées de bottle Homebrew sont disponibles pour 6 plateformes.
  • S’installe avec 1 dépendances d’exécution.
  • Les métadonnées de compilation listent 1 dépendances de compilation.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

exécutables

Exécutables installés

CommandeTypeExpositionNote
osslsigncodecliexécutable global

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-07-26
version du gestionnaire2.14
gestionnaire mis à jour2026-07-21
données localesOK
amontà jour
dernière version détectée2.14

https://github.com/mtrojnar/osslsigncode

  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:osslsigncode
Version2.14
Gestionnaire de paquetsHomebrew
Page du gestionnaire de paquetshttps://formulae.brew.sh/formula/osslsigncode
Page d'accueilhttps://github.com/mtrojnar/osslsigncode
Dépôthttps://github.com/mtrojnar/osslsigncode
Docs amonthttps://github.com/mtrojnar/osslsigncode#readme
LicenceGPL-3.0-or-later
Archive sourcehttps://github.com/mtrojnar/osslsigncode/archive/refs/tags/2.14.tar.gz
Dernière mise à jour2026-07-21T00:23:43Z
Pulseupdated
Dépendancesopenssl@3
Dépendances de compilationcmake
Bibliothèques fournies par macOScurl, python
Bouteilledisponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
post-install Homebrewnon défini
Serviceaucun déclaré

faits du registre

Détails de la base source

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameosslsigncode
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

Debian apt95%

osslsigncode 2.9-2

Authenticode signing tool

https://github.com/mtrojnar/osslsigncode

sudo apt install osslsigncode
  • Section: otherosfs
  • Architecture: amd64
  • 3 Dépendances
  • normalized package name match
  • Correspondance par : Osslsigncode
Debian stable package indexes · deb.debian.org · Debian stable package indexes: osslsigncode from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz
Nix95%

osslsigncode

nix profile install nixpkgs#osslsigncode
  • normalized package name match
  • Correspondance par : Osslsigncode
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/os/osslsigncode/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Ubuntu apt95%

osslsigncode 2.8-2

Authenticode signing tool

https://github.com/mtrojnar/osslsigncode

sudo apt install osslsigncode
  • Section: universe/otherosfs
  • Architecture: amd64
  • 4 Dépendances
  • normalized package name match
  • Correspondance par : Osslsigncode
Ubuntu 24.04 LTS package indexes · archive.ubuntu.com · Ubuntu 24.04 LTS package indexes: osslsigncode from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz
dnf95%

osslsigncode 2.13-1.fc45

OpenSSL-based Authenticode signing for PE, CAB, CAT, MSI, APPX

https://github.com/mtrojnar/osslsigncode

sudo dnf install osslsigncode
  • License: GPL-3.0-or-later
  • Category: Unspecified
  • Architecture: x86_64
  • Source Package: osslsigncode
  • 5 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Osslsigncode
Fedora Rawhide package metadata · dl.fedoraproject.org · Fedora Rawhide package metadata: osslsigncode from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/e5ca8ce900cd68f5419e1c39ae517343100b306336cbaeb70a3c153121d95094-primary.xml.zst
zypper95%

osslsigncode 2.13-1.2

Platform-independent tool for Authenticode signing of EXE/CAB files

https://github.com/mtrojnar/osslsigncode

sudo zypper install osslsigncode
  • License: GPL-3.0-only
  • Category: Productivity/Security
  • Architecture: x86_64
  • Source Package: osslsigncode
  • 4 Dépendances
  • 1 fournit
  • normalized package name match
  • Correspondance par : Osslsigncode
openSUSE Tumbleweed package metadata · download.opensuse.org · openSUSE Tumbleweed package metadata: osslsigncode from https://download.opensuse.org/tumbleweed/repo/oss/repodata/be8d3611d25469107f32075a1697e69ec57a2b850b42348a658cc671ad5ec2b50760d02c3e59524d50da9a11d5be799bdaffba2e166e8ca8858512e3c0bd665d-primary.xml.zst
MacPorts95%

osslsigncode

sudo port install osslsigncode
  • normalized package name match
  • Correspondance par : Osslsigncode
MacPorts ports tree · api.github.com · MacPorts ports tree: devel/osslsigncode/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
Scoop95%

main/osslsigncode

scoop install main/osslsigncode
  • normalized package name match
  • Correspondance par : Osslsigncode
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/osslsigncode.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1
winget95%

MichalTrojnara.osslsigncode

winget install --id MichalTrojnara.osslsigncode -e
  • normalized package name match
  • Correspondance par : Osslsigncode
Windows Package Manager source index · cdn.winget.microsoft.com · Windows Package Manager source index: MichalTrojnara.osslsigncode from https://cdn.winget.microsoft.com/cache/source.msix

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment