Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Sign release binaries and images #94

Merged
merged 1 commit into from
Jan 11, 2024

Conversation

stefanb
Copy link
Contributor

@stefanb stefanb commented Jan 10, 2024

Signing steps from example https://github.com/goreleaser/goreleaser-example-slsa-provenance applied to rye repo.

Tested in my fork, see:

Scorecard for my fork confirms that latest test releases are signed there: https://securityscorecards.dev/viewer/?uri=github.com/stefanb/rye
image


Feel free to try squash-merge option when merging the PR:
image
(if that option is not available you may need to enable it in repositroy settings)

@refaktor
Copy link
Owner

Thank you. I have to study this a little more for what I have to do then at releases.

@refaktor refaktor merged commit 554086e into refaktor:main Jan 11, 2024
7 checks passed
@stefanb stefanb deleted the signed-release-binaries branch January 11, 2024 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants