universal package signing
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 9.2k
- Forks
- 1.3k
- Avg merge
- 12h 58m
- Merged PRs (30d)
- 56
Description
Supply chain attacks on software packages are a great risk for open source software and it use. Maven jars, nodejs packages, pypi, ruby gems etc. are often not signed, because developers find it too hard. (source: Sonatype) If we make keybase the heart of a "letssign" project (analogous to letsencrypt) a big improvement can be made in securing the use of open source libraries. At npmjs they already have started their signing efforts (see https://blog.npmjs.org/post/172999548390/new-pgp-machinery) . Please advice. If keybase if not the place for this feature request, please propose an alternative organisation or team to turn to.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or implementation entry points are identified. Start by reviewing Keybase's role and the linked npm PGP machinery, then compare signing needs across Maven, Node.js, PyPI, and RubyGems; the issue would need a concrete scope and an agreed owner before implementation can be considered done.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, nodejs, python, ruby
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100