axodotdev / axodotdev/cargo-dist

signing: windows Trusted Signing

Open
#1,122 0 comments 0 reactions 0 assignees View on GitHub
feature request - new integration supplychain security
Dominant language
Rust
Stars
2.1k
Forks
149
Avg merge
1d 11h
Merged PRs (30d)
32

Description

This is in preview but Microsoft [announced their own first-party streamlined solution for code signing](https://techcommunity.microsoft.com/t5/security-compliance-and-identity/trusted-signing-is-in-public-preview/ba-p/4103457) which is probably gonna be ideal for us to support as the "one true windows code signing solution". However right now there's a rough restriction that a company needs to exist for 2 years (2 tax-filings) for them to qualify for a certificate.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by reviewing cargo-dist’s existing Windows code-signing flow and the Microsoft Trusted Signing requirements; done means the project has a clearly defined, supported integration for this signing service.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.