modelcontextprotocol / modelcontextprotocol/csharp-sdk
Release signed binaries in nuget package
Nobody has claimed this yet.
- Dominant language
- C#
- Stars
- 4.5k
- Forks
- 814
- Avg merge
- 9d 19h
- Merged PRs (30d)
- 4
Description
Is your feature request related to a problem? Please describe.
Unsigned binaries are a gap in the supply chain, allowing attackers a way in.
Describe the solution you'd like
All binaries in the released nuget packages are signed.
Describe alternatives you've considered
N/A
Additional context
N/A
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue does not name files, tests, or release entry points. Start by locating the repository's package and release configuration, then determine how signing can be applied to every binary in released NuGet packages; done means the published package contents are signed and the release process verifies that state.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100