Skip to content

Sign the release assets, and keep the signing key in the repository #106

Description

@moezdil

Nothing on a release is signed. Someone who downloads siltide-linux-amd64 can compare it against checksums.txt, which is only as trustworthy as the page that served both.

A detached signature per asset, and a KEYS file at the repository root holding the current key and the retired ones so older releases stay verifiable, would let a download be verified against a key that came from this repository rather than a keyserver search, where anyone can upload a key under any name. The verify step then belongs in the install instructions, and a stable release should only go public once signing has succeeded.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions