microsoft / microsoft/component-detection
Sign Component Detection GitHub releases
未關閉
@FernandoRojo 已經在處理了。
開始於 2024年5月21日。
status:requirements
type:ci
- 主要語言
- C#
- 星號
- 553
- 分支
- 135
- 平均合併
- 20 小時 58 分鐘
- 30 天內合併 PR
- 6
描述
In accordance with OpenSSF's recommendations, we should be cryptographically signing our GitHub releases with a GPG key.
- OpenSSF Guidance: https://github.com/ossf/scorecard/blob/4edb07802fdad892fa8d10f8fd47666b6ccc27c9/docs/checks.md#signed-releases
- Doc on signing releases from debian: https://wiki.debian.org/Creating%20signed%20GitHub%20releases
We can perhaps use the cert from OneCert when we complete #652
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
評估
這個 Issue 還沒有評估資料。