Skip to content

Package signing

Kartheek Penagamuri edited this page Jan 28, 2020 · 24 revisions

Status: Reviewed

This specification is one part of a new experience for package signing described in the blog post: NuGet Package Signing.

Package Signatures Master Spec List

Here you can find a list of the relevant specifications. Some of these require more work and details to be added, that we plan to do shortly – while some are further along. They are grouped by the three stages described in the blog post NuGet Package Signing.

The work for this feature and the discussion around the spec is tracked here: #2577 Package Signing

Stage 1. Enable package authors to sign their packages

Stage 2. Tamper proofing entire package dependency graphs

Stage 3. Configurable policies to enable locked down developer environments

Contributing

What's Being Worked On?

Check out the proposals in the accepted & proposed folders on the repository, and active PRs for proposals being discussed today.

Common Problems

Clone this wiki locally