keybase / keybase/client

universal package signing

Open
#14,877 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

Supply chain attacks on software packages are a great risk for open source software and it use. Maven jars, nodejs packages, pypi, ruby gems etc. are often not signed, because developers find it too hard. (source: Sonatype) If we make keybase the heart of a "letssign" project (analogous to letsencrypt) a big improvement can be made in securing the use of open source libraries. At npmjs they already have started their signing efforts (see https://blog.npmjs.org/post/172999548390/new-pgp-machinery) . Please advice. If keybase if not the place for this feature request, please propose an alternative organisation or team to turn to.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or implementation entry points are identified. Start by reviewing Keybase's role and the linked npm PGP machinery, then compare signing needs across Maven, Node.js, PyPI, and RubyGems; the issue would need a concrete scope and an agreed owner before implementation can be considered done.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, nodejs, python, ruby
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.