Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate SLSA signature / provenance for your artifacts #272

Open
laurentsimon opened this issue Sep 15, 2022 · 0 comments
Open

Generate SLSA signature / provenance for your artifacts #272

laurentsimon opened this issue Sep 15, 2022 · 0 comments
Labels
enhancement New feature or request
Milestone

Comments

@laurentsimon
Copy link

laurentsimon commented Sep 15, 2022

Hi,

I'm reaching out on behalf of the Open Source Security Foundation (openssf.org), a project of the Linux Foundation. We work on improving the security of critical open source projects like yours.

Together with GitHub, we designed a free, easy-to-use method of code signing It will help your users verify that your release artifacts were built from your repository’s and not altered by anyone. It’s just a few lines of code, but it will make your project more secure against third-party tampering and attacks like attacks like Codecov and CTX.

You don’t have to be a cryptography expert or learn complicated tools and verification is simple for your users. There are examples here to integrate with GoReleaser, for example.

We have onboarded several projects already, including urllib3, flatbuffers and grpc-gateway.

It would be great to see your repository generate SLSA provenance as well!

@laurentsimon laurentsimon added the enhancement New feature or request label Sep 15, 2022
@nishakm nishakm added this to the Release 0.1.0 milestone Sep 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants