4 ms·
Dear GitHub CEO reading this message on HN: a cool feature would be a GitHub action to sign binaries for free. It's ridiculous that my open source code is host
by fierarul 6y ago
Dear GitHub CEO reading this message on HN: a cool feature would be a GitHub action to sign binaries for free.
It's ridiculous that my open source code is hosted on GitHub, the binary is created with an action but I have to pay for a certificate and manually sign it.
- gschrader 6y agoYes this please! I recently found out the hoops one must jump through to sign code, I've basically have given up until one of the CI services will provide a way.
- magicalhippo 6y agoI guess since Microsoft through GitHub controls the build process, couldn't they also include the signed source as well as a combined signature? Idea being that one could, in theory, download the git repo, check out the relevant commit and verify that this was the source code and this was the resulting binary, and that matches the exe file I just downloaded.
- fierarul 6y agoYes! I bet there are numerous ways this could be implemented to make things easier for developers and end users. With the current setup GitHub has more control on the resulting bits than I do. Also, current Microsoft signature rules that a hardware dongle is required to sign the bits (all non-hardware certificates will be deprecated in time). So, I'm supposed to take the .EXE that GitHub produced on one of their VMs running actions then certify it's legit by signing it with my certificate. But what am I actually certifying? Well, that to the best of my knowledge this EXE is the build output of this Git commit that triggered the action.