Yes, it’s standard practice to just use one certificate to sign all distributions.
I previously worked at 2 very large, well-known software companies, and they both did. Each of them had their own protocols / systems to limit who can create binary files using a certificate.
source
share