GPG Sign Releases
Open
CKAN Infrastructure
enhancement
- Dominant language
- No language data
- Stars
- 39
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
i think we should [sign releases](http://driesvints.com/blog/using-a-gpg-key-to-sign-off-git-commits-and-emails)
Contributor guide
No contributing guide indexed for this repository
Research direction
This issue contains no files, tests, or entry points to inspect and only proposes signing releases. Start by reviewing the linked GPG guide and the current release process in the main CKAN project, then define the signing and verification scope before implementation.
Written by the indexing model from the issue text.
Assessment
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100