2 ms·
Provenance artifacts via something like SigStore would go a long way, since it solves both key management and the linking of artifacts to their build process.
by Bognar 3y ago
Provenance artifacts via something like SigStore would go a long way, since it solves both key management and the linking of artifacts to their build process.
For Go where you're just publishing sources with a build necessarily, you could opt for SigStore git signing so you can at least validate the author via a 2FA auth provider's OIDC token.