microsoft / microsoft/component-detection
Sign Component Detection GitHub releases
未关闭
@FernandoRojo 已经在做这个了。
开始于 2024年5月21日。
status:requirements
type:ci
- 主要语言
- C#
- 星标
- 553
- 派生
- 135
- 平均合并
- 20 小时 58 分钟
- 30 天内合并 PR
- 6
描述
In accordance with OpenSSF's recommendations, we should be cryptographically signing our GitHub releases with a GPG key.
- OpenSSF Guidance: https://github.com/ossf/scorecard/blob/4edb07802fdad892fa8d10f8fd47666b6ccc27c9/docs/checks.md#signed-releases
- Doc on signing releases from debian: https://wiki.debian.org/Creating%20signed%20GitHub%20releases
We can perhaps use the cert from OneCert when we complete #652
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
评估
这个 Issue 还没有评估数据。