Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detached signature for release source code tarballs #11

Open
arkevmitch opened this issue Mar 17, 2023 · 0 comments
Open

Detached signature for release source code tarballs #11

arkevmitch opened this issue Mar 17, 2023 · 0 comments

Comments

@arkevmitch
Copy link

Thanks for developing this useful library. Would it be possible to include a detached signature to authenticate the release tarballs?

While simply signing git release tags or even commits would be a step in the right direction, signing the actual released artifacts would be a huge help to users concerned about code authenticity.

It's not foolproof, but if the public key is published to a keyserver like https://keyserver.ubuntu.com/ in addition to someplace independent (like a developers website or maybe even somewhere here on github), then it can be used to provide a greater degree of confidence.

It looks like it should be a pretty straightforward process and would be much appreciated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant