cjcliffe / CubicSDR

Cross-Platform Software-Defined Radio Application
http://www.cubicsdr.com
GNU General Public License v2.0
2.02k stars 249 forks source link

Please digitally sign your release tarballs #998

Open jscott0 opened 1 year ago

jscott0 commented 1 year ago

Hi, For downstreams to verify the integrity of the source code, it would be nice if you would sign releases with either an OpenPGP key or an S/MIME certificate. Ideally such a key would be published in a secure DNS zone so folks could verify the validity of the key without relying on the Web of Trust or TOFU. Thanks!