-
Notifications
You must be signed in to change notification settings - Fork 187
Open
Labels
niceDown prioritizedDown prioritized
Description
Thanks for maintaining gitlab-ci-local!
This project uses rich releases at https://github.com/firecow/gitlab-ci-local/releases. Could you please consider also offering signatures alongside the tar.gz and other artifacts in your releases?
It is good practice in open source projects to publish cryptographic signatures alongside the tarball source releases, so that e.g. Linux distributions and other downstreams can use OpenPGP to verify the authenticity of the imported release.
This is not a hard requirement, just nice to have. Managing OpenPGP keys securely requires some effort. A good guide on the topic can be found at https://github.com/lfit/itpol/blob/master/protecting-code-integrity.md/
Metadata
Metadata
Assignees
Labels
niceDown prioritizedDown prioritized