bazel-contrib / bazel-contrib/buildtools
Buildtools release artifacts are unsigned and have no checksum files
- Dominant language
- Go
- Stars
- 1.2k
- Forks
- 471
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 13
Description
For the release binaries in github.com/bazelbuild/bazel, detached signatures are already provided. The release server also has a signature for the source archive, e.g.
https://releases.bazel.build/7.0.2/release/bazel_7.0.2.tar.gz
https://releases.bazel.build/7.0.2/release/bazel_7.0.2.tar.gz.sig
It would certainly be nice to have the same for buildtools, if possible.
Contributor guide
Research direction
Start by inspecting the buildtools release publishing process and how Bazel release artifacts receive detached signatures. Compare the buildtools artifacts with the referenced Bazel release and verify that each release binary and source archive has a detached signature and checksum file.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100