Expand description
SignalScreen signing-hygiene checker engine.
Pipeline: pe -> signature -> cert -> checks -> score -> report, wired by analyze().
Modules§
- cert
- Extract hygiene-relevant facts from the signer’s X.509 certificate.
- checks
- Run the hygiene checks over decoupled
Facts(easy to unit-test without parsing). - pe
- PE entry point: parse the file and extract the signer’s signature facts.
- report
- The report: canonical JSON (the contract every surface consumes) + human render.
- score
- Roll check results into a 0–100 score and an A–F grade. Pure — no parsing.
- signature
- Extract owned facts from a parsed Authenticode signature.
- timestamp
- When a signature was countersigned, and by whom.
Functions§
- analyze
- Analyze PE bytes and produce a hygiene report.
now_unixis injected for deterministic expiry checks (tests pass a fixed value; the CLI passes real time).