Skip to content

GPG signed verification of releases #1644

@jamesob

Description

@jamesob

Given the security-critical nature of this project, I think it would be preferable to have GPG-signed hashes available alongside source releases. Right now (AFAICT) this project is hinging completely on Github/HTTPS trust model when retrieving this repo for build and use.

Obviously the hashes and signatures GPG IDs would have to be posted somewhere aside from Github for full benefit.

I'm happy to help in whatever manner I can.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions