thoth-station / thamos

A CLI tool and library for communicating with Thoth
http://thoth-station.ninja
GNU General Public License v3.0
15 stars 17 forks source link

Sign releases with sigstore #923

Open fridex opened 2 years ago

fridex commented 2 years ago

Is your feature request related to a problem? Please describe.

As a user of Thoth, I would like to make sure releases of thamos are signed so that I can be sure about advises it provides to me.

Describe the solution you'd like

Sign Thamos releases.

Additional context

We should start signing releases of our components. We can start with user-facing parts, but also libraries running in the backend should be signed to make sure the whole application is secure.

codificat commented 2 years ago

/kind feature

codificat commented 2 years ago

Related: https://github.com/thoth-station/core/issues/345

goern commented 2 years ago

/priority important-longterm

sesheta commented 2 years ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

/lifecycle stale

mayaCostantini commented 2 years ago

https://github.com/trailofbits/sigstore-python

goern commented 2 years ago

/remove-lifecycle stale /priority important-soon /remove-priority important-longterm

sesheta commented 2 years ago

Issues go stale after 90d of inactivity. Mark the issue as fresh with /remove-lifecycle stale. Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

/lifecycle stale

mayaCostantini commented 2 years ago

/remove-lifecycle stale

mayaCostantini commented 2 years ago

/sig stack-guidance

codificat commented 2 years ago

A couple of related references: