dragonflydb / dragonflydb/dragonfly

Please add SLSA provenance to your releases

Open
#3,086 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
31.6k
Forks
1.3k
Avg merge
1d 10h
Merged PRs (30d)
137

Description

Thank you for your work on dragonfly.

However, given the nature of the modern world we live in, it would be nice if you could add [SLSA provenance](https://slsa.dev/) to your releases.

This could be through [Sigstore keyless signing](https://docs.sigstore.dev/signing/overview/), [Github artifact attestations](https://github.blog/changelog/2024-05-02-artifact-attestations-public-beta/) or any other method.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing how Dragonfly releases are built and published, then compare that process with the linked SLSA, Sigstore keyless signing, and GitHub artifact attestations guidance. Choose and document one provenance approach, and verify that published releases expose attestations that consumers can validate.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.