tensorchord / envd

🏕️ Reproducible development environment
https://envd.tensorchord.ai/
Apache License 2.0
1.93k stars 156 forks source link

feat: Sign images and release artifacts #1483

Open terrytangyuan opened 1 year ago

terrytangyuan commented 1 year ago

Description

We could use sigstore cosign for this. Read more on software supply chain security here: https://docs.sigstore.dev/#software-supply-chain-security


Message from the maintainers:

Love this enhancement proposal? Give it a 👍. We prioritise the proposals with the most 👍.

nitishchauhan0022 commented 1 year ago

/assign