Skip to content

Release that is signed ? #32

@jesper-arista

Description

@jesper-arista

Would it be possible to generate a release that is cryptographically signed with a key ?

It would allow us to import the signed release, and use the signature to verify the code is not modified.

For example tcpdump is available as a .tar.gz file at https://www.tcpdump.org/index.html#latest-releases with an associated signature https://www.tcpdump.org/release/libpcap-1.10.0.tar.gz.sig signed with a private key for which the public key is available at https://www.tcpdump.org/release/signing-key.asc

Any chance you could make this available ?

thanks
Jesper

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions