SumoLogic / sumologic-otel-collector

Sumo Logic Distribution for OpenTelemetry Collector
Apache License 2.0
41 stars 37 forks source link

Verifying collector installer #987

Open abstractOwl opened 1 year ago

abstractOwl commented 1 year ago

Hello! We're currently planning on automatically installing the SumoLogic OpenTelemetry collector for our services using a pre-deploy hook. Is there any way we can verify the collector binary or installer script (i.e. GPG signature) to mitigate against supply-chain attacks?

sumo-drosiek commented 1 year ago

For now there is no such way. We are considering adding checksums, so the binary would be verified against them