Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question: Is this the NuGet package #71

Closed
zahirtezcan-bugs opened this issue Jan 26, 2023 · 4 comments
Closed

Question: Is this the NuGet package #71

zahirtezcan-bugs opened this issue Jan 26, 2023 · 4 comments
Labels
question Further information is requested

Comments

@zahirtezcan-bugs
Copy link

Is this the NuGet package for this repository? If so is there a way to make yourself the verified publisher so people can find this repository via repository link?

@shacharPash shacharPash added the question Further information is requested label Jan 26, 2023
@shacharPash
Copy link
Contributor

@chayim

@chayim
Copy link
Contributor

chayim commented Jan 31, 2023

@zahirtezcan-bugs This is the nuget package. As a result, a README has been merged in as part of #76, and will appear in the upcoming release.

I don't see a lot of open-source implementing code signing. While #77 signs things using a GPG certificate, it currently cannot be pushed to nuget.org due to this design.

@zahirtezcan-bugs
Copy link
Author

Sorry if I was inconvenient but I am a mere simpleton when things come to security related issues. I thought the "tick" next to the a package could be easier on the uploader account side of things other than signing packages.

I thought it was related to verified: true entry in related package query. What I was asking can be seen on StackExchange.Redis package nuget page. Where they have a "tick" under package name, and have links to project website and github repository on the right side of the page.

Since this was a question other than a feature request, thanks for the answers. Feel free to close this issue whenever you deem finished.

@chayim
Copy link
Contributor

chayim commented Feb 1, 2023

@zahirtezcan-bugs all good, I'm glad you asked! I think the "tick" occurs there due to them owning the underlying prefix. I've left the code-signing item open, as we think / figure it out. Will close accordingly!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

3 participants