You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Maybe we could sign the binary and upload the binary and its signature to the interim artifacts.
The signatures could be checked when building the container image. I suppose this may be needed for SLSA.
Not much improvement for our current security stance, as we depend on GHA and artifacts anyway. But in the future we could build in our own worker.
Maybe we could sign the binary and upload the binary and its signature to the interim artifacts.
The signatures could be checked when building the container image. I suppose this may be needed for SLSA.
Not much improvement for our current security stance, as we depend on GHA and artifacts anyway. But in the future we could build in our own worker.
Originally posted by @viccuad in #312 (comment)
The text was updated successfully, but these errors were encountered: