Open msabramo opened 8 years ago
to give users an extra sense of security that they have a real, untampered-with download.
Example: See the consul_0.6.4_SHA256SUMS file at https://releases.hashicorp.com/consul/0.6.4/
consul_0.6.4_SHA256SUMS
Bonus points if you sign the file with a GPG key -- e.g.: consul_0.6.4_SHA256SUMS.sig
consul_0.6.4_SHA256SUMS.sig
Will this ever be implemented? I have no extra sense of security
I will get this into the CI/CD pipeline
to give users an extra sense of security that they have a real, untampered-with download.
Example: See the
consul_0.6.4_SHA256SUMS
file at https://releases.hashicorp.com/consul/0.6.4/Bonus points if you sign the file with a GPG key -- e.g.:
consul_0.6.4_SHA256SUMS.sig