Replace GnuPG with Sequoia
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 1.6k
- Forks
- 211
- Avg merge
- 4d 21h
- Merged PRs (30d)
- 6
Description
**Is your feature request related to a problem? Please describe.**
GnuPG is a large amount of legacy C code that operates on untrusted input.
**Describe the solution you'd like**
Use Sequoia instead. Only signature verification is needed.
**Describe alternatives you've considered**
Use a different tool for verifying signatures, such as signify or ssh-keygen.
**Additional context**
GnuPG has known bugs and will decompress data in the signature, creating extra attack surface.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the current GnuPG signature-verification integration and documenting its entry points and verification flow. Assess how Sequoia can provide signature verification only, then define completion as replacing the GnuPG path while preserving required verification behavior and avoiding its decompression of signed data.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100