You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The GitHub release asset metadata currently reports a null digest, and I have not located an official published checksum. I would appreciate clarification on the following points.
Official artifact digest
Does WiX retain an official SHA256, SHA512, other cryptographic digest, or checksum manifest for this exact release asset?
If so, please provide the digest and an official reference identifying the asset it covers. Please distinguish any historical SHA1 record from a modern integrity verification mechanism.
Source-to-binary provenance
Are there any signed manifests, build provenance records, attestations, reproducible-build records, or release build records that bind the wix3141rtm source/tag to the bytes of this ZIP?
If available, please identify the source commit and artifact digest covered by those records.
Authenticode signing coverage
For the files needed to run dark.exe -x from this portable distribution:
Which files are expected to have Authenticode signatures?
What signer/publisher identity should be expected for this release?
Are expected certificate identifiers and timestamp details documented?
Is there an official complete signed-file manifest?
Does signing coverage include dark.exe, winterop.dll, and all required managed assemblies?
Which required files, including configuration and resources, are unsigned, and how should their integrity be verified?
Minimum dependency closure
For this invocation only:
dark.exe -nologo -x
What is the minimum required binary/configuration/resource dependency set in the official v3.14.1 portable distribution?
Does the default configuration load extensions that are unnecessary for Burn bundle extraction? Is there an officially supported configuration for this operation that avoids loading those extensions without changing the tool binaries or its extraction behavior?
Historical asset verification
If no public digest or provenance page is available, does WiX retain historical release records that can verify the original release bytes associated with Asset ID 158158052?
Please also clarify whether the currently distributed asset is the original asset or has been replaced, and identify any official verification procedure available for it.
This inquiry concerns artifact verification only. I am not requesting republication or modification of the historical release, or endorsement of an application. No files are attached.
If another official channel or maintainer holds these records, please direct me to that contact.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Question
Hello WiX Toolset maintainers,
I am evaluating the WiX v3.14.1 portable binaries for offline static inspection of a WiX Burn v3 bundle without executing the target installer.
Could you help confirm the integrity and provenance of this specific historical release asset?
Repository: wixtoolset/wix3
Release tag: wix3141rtm
Release ID: 148004296
Asset name: wix314-binaries.zip
Asset ID: 158158052
Recorded size: 41,297,555 bytes
Release URL: https://github.com/wixtoolset/wix3/releases/tag/wix3141rtm
Asset URL: https://github.com/wixtoolset/wix3/releases/download/wix3141rtm/wix314-binaries.zip
The GitHub release asset metadata currently reports a null digest, and I have not located an official published checksum. I would appreciate clarification on the following points.
Official artifact digest
Does WiX retain an official SHA256, SHA512, other cryptographic digest, or checksum manifest for this exact release asset?
If so, please provide the digest and an official reference identifying the asset it covers. Please distinguish any historical SHA1 record from a modern integrity verification mechanism.
Source-to-binary provenance
Are there any signed manifests, build provenance records, attestations, reproducible-build records, or release build records that bind the wix3141rtm source/tag to the bytes of this ZIP?
If available, please identify the source commit and artifact digest covered by those records.
Authenticode signing coverage
For the files needed to run dark.exe -x from this portable distribution:
Which files are expected to have Authenticode signatures?
What signer/publisher identity should be expected for this release?
Are expected certificate identifiers and timestamp details documented?
Is there an official complete signed-file manifest?
Does signing coverage include dark.exe, winterop.dll, and all required managed assemblies?
Which required files, including configuration and resources, are unsigned, and how should their integrity be verified?
Minimum dependency closure
For this invocation only:
dark.exe -nologo -x
What is the minimum required binary/configuration/resource dependency set in the official v3.14.1 portable distribution?
Does the default configuration load extensions that are unnecessary for Burn bundle extraction? Is there an officially supported configuration for this operation that avoids loading those extensions without changing the tool binaries or its extraction behavior?
Historical asset verification
If no public digest or provenance page is available, does WiX retain historical release records that can verify the original release bytes associated with Asset ID 158158052?
Please also clarify whether the currently distributed asset is the original asset or has been replaced, and identify any official verification procedure available for it.
This inquiry concerns artifact verification only. I am not requesting republication or modification of the historical release, or endorsement of an application. No files are attached.
If another official channel or maintainer holds these records, please direct me to that contact.
Thank you for your assistance.
Open Source Maintenance Fee
wixtoolsetproject because I support the maintainers.All reactions