Mozilla are lucky enough to be able to afford a code-signing certificate and I'm pretty sure their build process can be adjusted to sign binaries by default.
It's unfortunate that a LetsEncrypt style project can't be done for code signing, due to malware/admin overhead.
It's unfortunate that a LetsEncrypt style project can't be done for code signing, due to malware/admin overhead.