3 ms·
Yes! I bet there are numerous ways this could be implemented to make things easier for developers and end users. With the current setup GitHub has more control
by fierarul 6y ago
Yes! I bet there are numerous ways this could be implemented to make things easier for developers and end users.
With the current setup GitHub has more control on the resulting bits than I do.
Also, current Microsoft signature rules that a hardware dongle is required to sign the bits (all non-hardware certificates will be deprecated in time).
So, I'm supposed to take the .EXE that GitHub produced on one of their VMs running actions then certify it's legit by signing it with my certificate.
But what am I actually certifying? Well, that to the best of my knowledge this EXE is the build output of this Git commit that triggered the action.