Recently downloaded and Microsoft Defender SmartScreen is categorizing Emacs as malicious.
Emacs-31.1-installer.exe was released very recently (August 24, 2026), so a new Windows installer having little reputation is quite plausible.
It doesn’t necessarily mean GNU Emacs is malicious. The screenshot is showing a Windows reputation warning, and there are two clues that explain it:
“Publisher: Unknown publisher” — Windows cannot establish a trusted code-signing identity for that particular .exe.
Microsoft Defender SmartScreen considers both the publisher's reputation and the specific file's download/reputation history. A legitimate but newly released or infrequently downloaded executable can therefore trigger a warning. Microsoft explicitly says that unknown programs are not necessarily malicious.
This happens to all innovative and novel software, and developers like me who struggle to convince your software is safe, even to governmental security agencies.


No comments:
Post a Comment
Use at your own risk.