dragonflydb / dragonflydb/dragonfly
Please add SLSA provenance to your releases
- Dominant language
- C++
- Stars
- 31.6k
- Forks
- 1.3k
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 137
Description
Thank you for your work on dragonfly.
However, given the nature of the modern world we live in, it would be nice if you could add [SLSA provenance](https://slsa.dev/) to your releases.
This could be through [Sigstore keyless signing](https://docs.sigstore.dev/signing/overview/), [Github artifact attestations](https://github.blog/changelog/2024-05-02-artifact-attestations-public-beta/) or any other method.
Contributor guide
Research direction
Start by reviewing how Dragonfly releases are built and published, then compare that process with the linked SLSA, Sigstore keyless signing, and GitHub artifact attestations guidance. Choose and document one provenance approach, and verify that published releases expose attestations that consumers can validate.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100