axodotdev / axodotdev/cargo-dist

sign binaries with sigstore

Open
#120 13 comments 2 reactions 0 assignees View on GitHub
feature request feature request - new integration supplychain security
Dominant language
Rust
Stars
2.1k
Forks
149
Avg merge
1d 11h
Merged PRs (30d)
32

Description

As a developer I would like to have the ability to sign the binaries I release.

This could be done using [sigstore](https://github.com/sigstore) as they provide a fantastic keyless signing ecosystem (can use GitHub OIDC), as well as rust bindings [sigstore-rs](https://github.com/sigstore/sigstore-rs).

Contributor guide

Open the contributing guide

Research direction

Review the linked sigstore ecosystem and sigstore-rs bindings first, along with GitHub OIDC signing flows. The issue does not name repository files or tests; done would require a defined design and implementation for signing the binaries produced by cargo-dist.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, rust
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.