Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please sign release tarballs and/or release tags #345

Open
ottok opened this issue Nov 28, 2024 · 3 comments
Open

Please sign release tarballs and/or release tags #345

ottok opened this issue Nov 28, 2024 · 3 comments

Comments

@ottok
Copy link

ottok commented Nov 28, 2024

Hi!

While working on the Debian packaging for this Go program, I noticed that there are no *.asc signatures published at https://github.com/caarlos0/env/releases nor does the git tags in this project have signatures.

For better supply chain security, please consider signing both tags and release artifacts. Thanks!

@caarlos0
Copy link
Owner

caarlos0 commented Dec 6, 2024

will work on this when i have some time

@Juneezee
Copy link
Contributor

The Debian Wiki provides step-by-step instructions for this: https://wiki.debian.org/Creating%20signed%20GitHub%20releases.

However, the steps on the Wiki page are manual. I suggest automating the process using GitHub Actions, for example, by storing the private key as a GitHub Actions secret.

@ottok
Copy link
Author

ottok commented Dec 18, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants