Astral Details Code Signing for Its Toolchain, Extending to Ruff and ty

charliermarsh · x · 2026-09-10

Astral (charliermarsh) detailed how its distributed executables are secured: macOS binaries are signed with an Apple Developer ID certificate and notarized by Apple, while Windows executables carry timestamped Authenticode signatures from Azure Artifact Signing. The team says this work will be extended across the rest of the Astral toolchain, including Ruff and ty.

Original post →

More from coding & agent

coding & agent channel →