Signed releases
Open
area/build
area/security
enhancement
help wanted
- Dominant language
- C++
- Stars
- 28.9k
- Forks
- 5.6k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 437
Description
Running https://github.com/ossf/scorecard against https://github.com/envoyproxy/envoy gives generally a high score, but we are missing [signed](https://wiki.debian.org/Creating%20signed%20GitHub%20releases) releases/tags. The idea is to attach a GPG ASCII signature to the release/tag artifacts.
Arguably the benefit is marginal if we trust GitHub security (how many Envoy consumers will check this signature?), but this seems a reasonable defense-in-depth best practice to follow.
Contributor guide
Assessment
This issue has not been assessed yet.