Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add release atteststions #343

Open
orf opened this issue Oct 8, 2024 · 2 comments
Open

Add release atteststions #343

orf opened this issue Oct 8, 2024 · 2 comments

Comments

@orf
Copy link

orf commented Oct 8, 2024

Hello!

First, thanks for this fantastic project - it’s a great help to the community and ecosystem at large.

I would like to suggest adding artifact attestations to the releases.

This would enable supply chain verification for these builds, and provide a layer of validation above just verifying the signature.

it’s pretty simple to add: just a single step, with no configuration or changes required in the binary itself.

what do you think?

@zanieb
Copy link
Collaborator

zanieb commented Oct 8, 2024

Yeah these seem reasonable, were you interested in contributing this?

@orf
Copy link
Author

orf commented Oct 8, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants