Azure / Azure/azure-functions-core-tools

Sign all assets and Git tags in GitHub releases with Microsoft signing key

Open
#4,150 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
C#
Stars
1.5k
Forks
498
Avg merge
4d 20h
Merged PRs (30d)
14

Description

### Description

I want to be able to automate package creation for Arch Linux using the Linux binaries or build from the Git tags provided, without blindly trusting the assets/tags on the GitHub releases page.

OpenSSH signatures would be preferred, GPG is largely a legacy tool with much attack surface, OpenSSH makes more sense as it now ships in every major OS has much less attack surface.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or release entry points are named. Start by locating the workflow that builds and publishes GitHub release assets and tags, then verify how signing can use the requested Microsoft key. Done means every release asset and Git tag has a verifiable signature using the chosen signing method.

Written by the indexing model from the issue text.

Assessment

Tech stack
arch-linux, git, github
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.