Sources we trust
Primary sources are the MarkHopper24/barcodrod.io README, LICENSE.txt, Releases asset list, and SignPath policy text. Secondary sources are the product homepage and the Microsoft Store listing when cited as supporting.
What we re-check
On each review date we refresh gh.json, confirm MSI assetMatch picks, and re-read privacy and install methods. Commands not run on a real Windows PC stay labeled UNVERIFIED in research notes and are not described as observed behaviour.
What we refuse
We refuse Softonic-style mirrors, invented winget IDs, hosted binaries, and barcode or scanner competing slots that were not approved for this qr code generator job.