bazel-contrib / bazel-contrib/buildtools

Buildtools release artifacts are unsigned and have no checksum files

Open
#1,239 2 comments 1 reaction 0 assignees View on GitHub
P2
Dominant language
Go
Stars
1.2k
Forks
471
Avg merge
2d 22h
Merged PRs (30d)
13

Description

For the release binaries in github.com/bazelbuild/bazel, detached signatures are already provided. The release server also has a signature for the source archive, e.g.

https://releases.bazel.build/7.0.2/release/bazel_7.0.2.tar.gz
https://releases.bazel.build/7.0.2/release/bazel_7.0.2.tar.gz.sig

It would certainly be nice to have the same for buildtools, if possible.

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the buildtools release publishing process and how Bazel release artifacts receive detached signatures. Compare the buildtools artifacts with the referenced Bazel release and verify that each release binary and source archive has a detached signature and checksum file.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.