mozilla-services / fx-sig-verify

DEPRECATED - Independent check of code signatures
Mozilla Public License 2.0
4 stars 13 forks source link

Consider checking PGP signatures as well. #66

Closed hwine closed 1 year ago

hwine commented 5 years ago

The release process uses autograph to sign many artifacts with a PGP detached signature. It is technically possible to extend fx-sig-verify to also check the validity of the detached signature.

Advantages

Disadvantages