Files
Maximilian Roos 60661a0d7e docs(signing): carry the SignPath attribution on the install section (#3709)
SignPath Foundation's OSS program requires the attribution notice, and a
route to the code signing policy, on a project's home page and
download/release pages. Worktrunk had both only on the policy page
itself — nothing on the README or the docs landing page. This puts the
notice in the install section's Windows block, beside the artifacts it
actually describes:

> Free code signing provided by [SignPath.io](https://signpath.io/),
certificate by [SignPath Foundation](https://signpath.org/) —
[policy](https://worktrunk.dev/code-signing/).

The edit is one line in `docs/content/worktrunk.md`; the README's
Install→Further reading block is generated from it, so it propagates
there and to both skill mirrors.

The policy page leaves the docs navigation in the same change, so this
is the single place it's linked from. `hide_from_nav = true` in a page's
`[extra]` skips it in all three loops over `docs_section.pages`: the
desktop TOC (`macros.html`), the mobile menu (`base.html`), and the
prev/next flow nav (`page.html`). The page stays published and reachable
at `/code-signing/` — unlisted, not removed.

In the nav loops the skip wraps the whole per-page body, so a hidden
page can't emit a stray group heading. In the prev/next loop it guards
only the *candidate* assignments — the current-page test stays
unguarded, because viewing a hidden page directly must still flip
`found_current` or its own neighbours compute against the wrong page.
Verified both directions: FAQ ends at `← Tips & Patterns` with no
forward link, and the policy page keeps `← FAQ` back out into the docs.

<details><summary>Why this came up, and the placement tradeoff</summary>

Found while debugging why the `release-signing` signing policy shows
INVALID in the SignPath console. That turned out to be unrelated and not
fixable here — its certificate ("Release certificate 2026", subject
`CN=SignPath Foundation`, on SignPath's HSM) is in `CSR PENDING` with no
validity dates, awaiting CA issuance. The policy's own configuration is
complete and correct. Worktrunk currently signs with the test
certificate, which is VALID.

The attribution gap was the one thing found on our side. Whether it
bears on the pending review is unknown — the console exposes no
application status.

On placement: the notice sits inside the collapsed `<details>`, so it
isn't visible until a reader expands "Windows & other". That's
deliberate — the signing is Windows-specific and the notice reads better
next to it than in the page chrome — but it is the least prominent
placement that still counts as a link, and the terms ask for the notice
*on* the home and download pages. Worth knowing if placement is ever
queried during review.

</details>

> _This was written by Claude Code on behalf of max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-02 10:53:46 -07:00
..