Sign binary releases
Open
distribution
- Dominant language
- Rust
- Stars
- 659
- Forks
- 36
- Avg merge
- 18m
- Merged PRs (30d)
- 2
Description
I should sign release binaries. However, the binaries are produced on GitHub actions, and I have no way to verify that the build was completed faithfully. The best way to do this is probably with deterministic builds. However, I don't have a trusted linux box on which to build, so that's a prerequisite to signing binaries.
Contributor guide
Assessment
This issue has not been assessed yet.