Immutable Releases [Preview]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
Immutable Releases introduces enhanced integrity and security for software distributed via GitHub Releases. With this feature, repository maintainers can publish releases and associated assets as immutable, ensuring that once a release is published, its assets and associated Git tag cannot be altered or deleted. This prevents supply chain attacks that rely on asset modification or tag movement after publication, and provides users with stronger guarantees that the artifacts they consume are exactly as originally published. Immutable Releases also introduces release attestations, allowing consumers to verify the origin and integrity of artifacts—even outside of GitHub.
### Expected Outcome
- Organizations and open-source projects can confidently distribute software through GitHub Releases, knowing assets and tags cannot be tampered with after publication.
- Consumers and downstream automation will be able to reliably verify that downloaded artifacts are authentic and unmodified, reducing risk in the software supply chain.
- The introduction of release attestations provides verifiable proof of artifact origin and content, supporting secure end-to-end software delivery.
- Immutable Releases aligns GitHub Releases with best practices for provenance and immutability, supporting compliance, security, and trust for all users.
贡献指南
调研方向
No repository files, tests, or implementation entry points are identified in this roadmap issue. Start by clarifying the implementation scope and relevant GitHub Releases and attestation components with maintainers; done should provide immutable releases, protected assets and tags, and verifiable artifact provenance.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github
- 领域
- release, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 20/100