* Sign Windows engine releases with Azure Artifact Signing
Isolate OIDC signing behind a maintainer-approved release environment and publish only verified, timestamped company-signed Windows output.
AI assistance: implemented and verified with Codex under maintainer direction.
* Clarify same-run artifact permissions
Keep least-privilege tokens: the pinned artifact actions use ACTIONS_RUNTIME_TOKEN for same-run transfers. Guard against opting into cross-run downloads and use role-based reviewer wording.
AI assistance: prepared and verified with Codex under maintainer direction.