Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signed commits/tags/tarballs #120

Closed
shibumi opened this issue Aug 17, 2018 · 4 comments
Closed

Signed commits/tags/tarballs #120

shibumi opened this issue Aug 17, 2018 · 4 comments
Labels

Comments

@shibumi
Copy link

shibumi commented Aug 17, 2018

Hello,
I am the maintainer of the arch linux package. It would be super nice if you could sign your commits/tags and your tarballs via GPG for reliable secure releases.

How you do this is explained here:

https://help.github.com/articles/signing-commits-using-gpg/
https://wiki.debian.org/Creating%20signed%20GitHub%20releases

tarballs are not so important for me. I would be happy with signed commits and tags.

@shibumi
Copy link
Author

shibumi commented Sep 21, 2018

Hi,
Any update in this direction? It would be really nice to have releases that are provable secure.

@github-actions
Copy link
Contributor

This issue has been marked as stale because it has not had recent activity. The bot will close the issue if no further action occurs.

@github-actions github-actions bot added the stale label Jan 10, 2020
@LKaemmerling
Copy link
Member

We are currently working on overhauling the release process for the hcloud cli. With the next release, we will have signed binaries, releases and archives.

@shibumi
Copy link
Author

shibumi commented Jan 10, 2020

@LKaemmerling can we leave this open, until you fixed this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants