I tried uploading it to their web-thing so it could be examined in detail and verified but the installer was too large for it, apparently... some AV always false-positives it, it seems like.
Yeah, it's odd. I remember for the last release smartscreen would just take like 15+ minutes to scan the download, so most people thought the download had failed.
The executables aren't signed which is probably the main issue. They want executables to be signed with Extended Validation (EV) code signing certificates. It will get rid of the unknown publisher warning and over time I guess their AV will also start trusting you as a publisher.
Can also use OV code signing instead of EV (cheaper) but it will take longer for the executables to be trusted.
A self-signed certificate may be better than nothing. It's possible that it will help the reputation of the previous releases transfer over to the current ones.
It sounds like an EV code signing certificate will outright get rid of the warnings.
An OV code signing certificate is a lot cheaper and it won't be marked as from an unknown publisher but there will likely still be warnings. It would presumably get better over time though.