crossplane / crossplane

The Cloud Native Control Plane
https://crossplane.io
Apache License 2.0
9.09k stars 910 forks source link

Cryptographically signs release artifacts #4964

Open jeanduplessis opened 8 months ago

jeanduplessis commented 8 months ago

What problem are you facing?

To comply with the CLOMonitor checks, https://github.com/crossplane/crossplane/issues/4963, we need to sign all release artifacts.

How could Crossplane help solve your problem?

Update the release process to include signing of the release artifacts as per the instructions here: https://github.com/ossf/scorecard/blob/main/docs/checks.md#signed-releases

github-actions[bot] commented 5 days ago

Crossplane does not currently have enough maintainers to address every issue and pull request. This issue has been automatically marked as stale because it has had no activity in the last 90 days. It will be closed in 14 days if no further activity occurs. Leaving a comment starting with /fresh will mark this issue as not stale.