-
Notifications
You must be signed in to change notification settings - Fork 63
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Do Not trust verify #236
Comments
Could you please elaborate on what you are trying to achieve? This will help me guide you more effectively. |
Sure, i refer to something like that: |
I agree, this would be a really nice feature to have :) |
some additional reference I found in GitHub to sign a commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits |
All commits need to be signed in order for PR to be merged in the repo. I think what the OP refers to is for the releases to be signed so we don't have to trust GH |
Pls,
to avoid using bad source code, how to verify downloaded source code to build is that released?
The text was updated successfully, but these errors were encountered: