microsoft / microsoft/component-detection
Sign Component Detection GitHub releases
Đang mở
@FernandoRojo đang làm issue này rồi.
Từ ngày 21/5/2024.
status:requirements
type:ci
- Ngôn ngữ chính
- C#
- Star
- 553
- Fork
- 135
- Merge trung bình
- 20 giờ 58 phút
- Pull request đã merge (30 ngày)
- 6
Mô tả
In accordance with OpenSSF's recommendations, we should be cryptographically signing our GitHub releases with a GPG key.
- OpenSSF Guidance: https://github.com/ossf/scorecard/blob/4edb07802fdad892fa8d10f8fd47666b6ccc27c9/docs/checks.md#signed-releases
- Doc on signing releases from debian: https://wiki.debian.org/Creating%20signed%20GitHub%20releases
We can perhaps use the cert from OneCert when we complete #652
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Đánh giá
Issue này chưa được đánh giá.