the Signed-Releases
remediation steps encourage manual manipulation of the source code archives
#4018
Labels
Signed-Releases
remediation steps encourage manual manipulation of the source code archives
#4018
scorecard/docs/checks.md
Lines 607 to 613 in b577d79
In light of CVE-2024-3094, could the
Signed-Releases
remediation steps not encourage manual manipulation of the source code archives? :PFWIW, I filed this feature request for SLSA folks five months ago. Earlier today, I stopped waiting and wrote this workflow using Sigstore instead.
The text was updated successfully, but these errors were encountered: