ITADN

Support for signed source releases

#1318Openjfpanisset 创建于 2026-06-27
J
jfpanissetcommented
Several ASWF projects have implemented signed source releases. For instance in OpenEXR: https://github.com/AcademySoftwareFoundation/openexr/blob/main/.github/workflows/release-sign.yml This has a few advantages: - immutable source release, even if the release tag gets modified after the fact - visible SHA-256 checksum for the tarball - ability to programmatically verify authenticity of the tarball Unfortunately there doesn't seem to be a way to prevent the automatically generated links for unsigned .tar.gz and .zip archives from showing up. <img width="910" height="232" alt="Image" src="https://github.com/user-attachments/assets/cfe26385-d75c-4f5b-bbef-cdb179e4e142" />
0 条评论