Figure out our release signing process
Open
@lyoshenka is already working on this.
Since Nov 2, 2021.
- Dominant language
- Python
- Stars
- 7.2k
- Forks
- 493
- PR merge metrics
- No merged PRs in 30d
Description
Prompted by https://github.com/lbryio/lbry-desktop/issues/3424#issuecomment-955766035
Ideally:
- there's a single main key that delegates trust to the release signing keys
- remove references to Keybase since that's basically dead
- update https://lbry.com/faq/pgp-key to explain our policy and how to verify releases
- include lbry-desktop and lbcd in this system as well
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.