Consider signing release artifacts #2034
Labels
Build Issue
Issues related to build or environment problems on any platform.
good first issue
Standard label for new developers to locate good issues to tackle to learn about OCIO development.
help wanted
Issues that the TSC has decided are worth implementing, but don't currently have the dev resources.
The OpenSSF Best Practices Badge suggests signing release artifacts, using OpenEXR's release-sign.yml workflow as a template. It's triggered on release creation and does these steps:
get archive
to generate a<release>.tar.gz
artifact<release>.tar.gz
via sigstoreThe text was updated successfully, but these errors were encountered: