pop-os / system76-firmware

System76 Firmware Tool and Daemon
GNU General Public License v3.0
75 stars 28 forks source link

Sign release tags #124

Open DemiMarie opened 1 year ago

DemiMarie commented 1 year ago

Distribution (run cat /etc/os-release):

N/A

Related Application and/or Package Version (run apt policy $PACKAGE NAME):

N/A

Issue/Bug Description:

The release tags in this repository are not digitally signed. This prevents those who wish to package its contents for their own distributions from verifying the authenticity of those contents.

Steps to reproduce (if you know):

Check the Releases page.

Expected behavior:

Releases are digitally signed by a System76 OpenPGP or OpenSSH key.

Other Notes:

I would like to package this code for Qubes OS, a security-oriented operating system. Since Qubes OS provides protection against e.g. vulnerabilities in the Linux Wi-Fi stack, and Pop! OS does not, dual-booting is not desirable.