Skip to content

x/build: publish GPG signatures of downloads for releases #14739

Closed
@brianredbeard

Description

@brianredbeard

While providing SHA256 sums is helpful, it would be preferable to also validate that binary blobs are created by a trusted entity. Utilizing a GPG signing key and providing detached signatures (in .asc or .sig format) would allow users to automatically validate the heritage of a Golang tarball/MSI.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions