Lack of independently verifiable and tamper evident release decisions outside the platform #191913
Replies: 3 comments
-
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
Beta Was this translation helpful? Give feedback.
-
|
That’s a really insightful point having release decisions as standalone, tamper-evident artifacts would definitely strengthen trust, especially for audits and offline validation. It would also reduce dependency on a single platform as the source of truth. In a similar way, systems like haha pkr game download highlight how important it is to have reliable and verifiable processes built into the core experience for better transparency and security. |
Beta Was this translation helpful? Give feedback.
-
|
hey @88nonog-dev GitHub's strategic direction focuses on Artifact Attestations and Trusted Publishing to address the gap between platform-bound records and independent verifiability. This shift moves the source of truth from platform logs to cryptographically signed metadata that can travel with the artifact itself. [1, 2] Independent Verifiability vs. Platform RecordsGitHub views the transition toward "verifiable objects" through a few key lenses:
The "Decision as an Artifact"While current features focus heavily on how an artifact was built (provenance), GitHub is moving toward Release Attestations to ensure the decision to release was authentic. [2]
Current Gaps & Your ApproachGitHub acknowledges that purely platform-bound records are a security risk. While your approach of treating the release decision itself as a standalone artifact aligns with the broader industry move toward Zero Trust Supply Chains, the platform's current primary implementation of this is through Sigstore signatures and SLSA provenance. [3, 4, 9] Pls mark as accepted answer if this helps |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
from a
Beta Was this translation helpful? Give feedback.
All reactions