ossf / scorecard

OpenSSF Scorecard - Security health metrics for Open Source
https://scorecard.dev
Apache License 2.0
4.59k stars 498 forks source link

the `Signed-Releases` remediation steps encourage manual manipulation of the source code archives #4018

Open junyer opened 7 months ago

junyer commented 7 months ago

https://github.com/ossf/scorecard/blob/b577d79c96b76e6d3f17dd46003ac336b8ee4885/docs/checks.md?plain=1#L607-L613

In light of CVE-2024-3094, could the Signed-Releases remediation steps not encourage manual manipulation of the source code archives? :P

FWIW, I filed this feature request for SLSA folks five months ago. Earlier today, I stopped waiting and wrote this workflow using Sigstore instead.

github-actions[bot] commented 2 months ago

This issue has been marked stale because it has been open for 60 days with no activity.