Azure / Azure/azure-functions-core-tools
Sign all assets and Git tags in GitHub releases with Microsoft signing key
- Dominant language
- C#
- Stars
- 1.5k
- Forks
- 498
- Avg merge
- 4d 20h
- Merged PRs (30d)
- 14
Description
### Description
I want to be able to automate package creation for Arch Linux using the Linux binaries or build from the Git tags provided, without blindly trusting the assets/tags on the GitHub releases page.
OpenSSH signatures would be preferred, GPG is largely a legacy tool with much attack surface, OpenSSH makes more sense as it now ships in every major OS has much less attack surface.
Contributor guide
Research direction
No files, tests, or release entry points are named. Start by locating the workflow that builds and publishes GitHub release assets and tags, then verify how signing can use the requested Microsoft key. Done means every release asset and Git tag has a verifiable signature using the chosen signing method.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- arch-linux, git, github
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100