rstudio / rstudio/helm

Start signing Helm releases

Open
#244 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

security
Dominant language
Markdown
Stars
46
Forks
40
Avg merge
4h 3m
Merged PRs (30d)
6

Description

Helm supports signing and verifying chart releases with GPG, which is not as convenient as Cosign but might be better than nothing. To actually use GPG we will need:

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the GitHub Actions workflow that publishes Helm releases and the README templates used for generated charts. Check chart-releaser's existing GPG signing support and determine how RStudio's GPG key can be exposed to Actions. Done means releases are signed and the README templates explain how users can verify the signatures.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
devops, documentation, release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.