open-telemetry / sig-security

Apache License 2.0
7 stars 8 forks source link

Investigate code signing #10

Open codeboten opened 10 months ago

codeboten commented 10 months ago

Current PRs: https://github.com/open-telemetry/opentelemetry-collector-releases/pull/207

oly-baby commented 8 months ago

@jpkrohling and @codeboten

can i work on this issue

codeboten commented 8 months ago

@oly-baby sure, @jpkrohling please assign the PR as I just realized i don't have permissions to do so

jpkrohling commented 8 months ago

@oly-baby, we are blocked on the linked issue and I know @cpanato is interested in working on that, but you can investigate which other repositories could benefit from code signing as well. I would suppose that repositories generating consumable artifacts, like JARs, binaries, and OS-specific packages (deb/rpm/...) would benefit from this.

oly-baby commented 8 months ago

Alight