Open cary-ilm opened 2 months ago
The OpenSSF Best Practices Badge suggests signing release artifacts. Consider using OpenEXR's release-sign.yml workflow as a template. It's triggered on release creation and does these steps:
get archive
<release>.tar.gz
Oops, this duplicates #1782, but with a bit more explicit suggestions!
The OpenSSF Best Practices Badge suggests signing release artifacts. Consider using OpenEXR's release-sign.yml workflow as a template. It's triggered on release creation and does these steps:
get archive
to generate a<release>.tar.gz
artifact<release>.tar.gz
via sigstore