Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sign all assets and Git tags in GitHub releases with Microsoft signing key #4150

Open
the-gabe opened this issue Nov 6, 2024 · 0 comments
Open

Comments

@the-gabe
Copy link

the-gabe commented Nov 6, 2024

Description

I want to be able to automate package creation for Arch Linux using the Linux binaries or build from the Git tags provided, without blindly trusting the assets/tags on the GitHub releases page.

OpenSSH signatures would be preferred, GPG is largely a legacy tool with much attack surface, OpenSSH makes more sense as it now ships in every major OS has much less attack surface.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants