axodotdev / axodotdev/cargo-dist
sign binaries with sigstore
Open
feature request
feature request - new integration
supplychain security
- Dominant language
- Rust
- Stars
- 2.1k
- Forks
- 149
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 32
Description
As a developer I would like to have the ability to sign the binaries I release.
This could be done using [sigstore](https://github.com/sigstore) as they provide a fantastic keyless signing ecosystem (can use GitHub OIDC), as well as rust bindings [sigstore-rs](https://github.com/sigstore/sigstore-rs).
Contributor guide
Research direction
Review the linked sigstore ecosystem and sigstore-rs bindings first, along with GitHub OIDC signing flows. The issue does not name repository files or tests; done would require a defined design and implementation for signing the binaries produced by cargo-dist.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, rust
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100