Please sign release tarballs and/or release tags
- Dominant language
- Go
- Stars
- 6.3k
- Forks
- 284
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 1
Description
Hi!
While working on the Debian packaging for this Go program, I noticed that there are no *.asc signatures published at https://github.com/caarlos0/env/releases nor does the git tags in this project have signatures.
For better supply chain security, please consider signing both tags and release artifacts. Thanks!
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the repository's release process and the GitHub releases and git tags mentioned in the issue. Determine how signatures could be published and verified without exposing signing credentials. Done means release tarballs have corresponding .asc signatures and the git tags are signed and verifiable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100