Skip to content
This repository has been archived by the owner on Oct 6, 2019. It is now read-only.

Feature request: Signed releases #244

Open
avanier opened this issue Feb 8, 2018 · 2 comments
Open

Feature request: Signed releases #244

avanier opened this issue Feb 8, 2018 · 2 comments

Comments

@avanier
Copy link

avanier commented Feb 8, 2018

Would it be possible to have signed binary releases? Right now, if I want to get binaries that I know represent the code available at a given version, I have to pull from GitHub and compile the code myself.

GPG FTW.

@Typositoire
Copy link

That'd be nice indeed. You don't want fake packages to go leak all your secrets xD

@Caiyeon
Copy link
Owner

Caiyeon commented Feb 8, 2018

Yes, I have thought about signed releases and will likely do this in the future. Although, I'm not sure how far in the future. It probably won't be in the next release.

A signed package does not guarantee the source code from which it is compiled.

But the concern is valid. I, too, am paranoid, and would expect signed releases in the future.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants