Open psschwei opened 10 months ago
/sig release
/retitle Release artifacts are not signed
This is a result report of the #securitySlam
cc @alculquicondor @tenzen-y
Are there instructions on how to sign them?
The Kubernetes project currently lacks enough contributors to adequately respond to all issues.
This bot triages un-triaged issues according to the following rules:
lifecycle/stale
is appliedlifecycle/stale
was applied, lifecycle/rotten
is appliedlifecycle/rotten
was applied, the issue is closedYou can:
/remove-lifecycle stale
/close
Please send feedback to sig-contributor-experience at kubernetes/community.
/lifecycle stale
/lifecycle frozen
#SecuritySlam
What would you like to be added:
The project cryptographically signs release artifacts.
Why is this needed:
Signing artifacts would boost the security of the project. And since the CLOMonitor security score flags the project for not signing its artifacts, signing them would also make the score better.
Completion requirements:
These are the details from CLOMonitor around this task: