Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

General guideline on binary signing #2560

Open
reyang opened this issue May 20, 2022 · 2 comments
Open

General guideline on binary signing #2560

reyang opened this issue May 20, 2022 · 2 comments
Assignees
Labels
enhancement New feature or request spec:miscellaneous For issues that don't match any other spec label

Comments

@reyang
Copy link
Member

reyang commented May 20, 2022

We don't yet have a guideline regarding how language SIGs should sign the binaries that they release.
We're seeing asks from multiple SIGs:

A possible solution would be sigstore, which is making good progress:

Additional info & ideas:

@cpanato
Copy link

cpanato commented Nov 17, 2022

let me know where i can help. :)

@reyang
Copy link
Member Author

reyang commented Nov 19, 2022

let me know where i can help. :)

@cpanato thank you! I think an OTEP would be a great starting point.

(@jsuereth FYI)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request spec:miscellaneous For issues that don't match any other spec label
Projects
None yet
Development

No branches or pull requests

3 participants