This repository contains an automatically updated bundle
of Microsoft's root store for code signing, i.e. certificates
with the codeSigning
EKU.
The bundle is available in bundle.pem.
This repository is virtually identical to the content provided by the CCADB. It serves only two purposes:
- To munge some additional metadata out of each certificate, for easier searching;
- To act as an (unauthenticated) transparency record for changes to Microsoft's root store, using Simon Willison's "Git scraping" idiom.