3 ms·
Haven't used them, but for open source, SignPath might be interesting, they do require transparent builds, but do support GitHub Actions: https://about.signpath
by eXpl0it3r 2y ago
Haven't used them, but for open source, SignPath might be interesting, they do require transparent builds, but do support GitHub Actions: https://about.signpath.io/product/open-source https://about.signpath.io/product/open-source
Some other signing that works in the cloud and has support for GitHub Actions would be DigiCert's KeyLocker (note: every signed binary is counted and by default the subscription only contains 1000 signings): https://www.digicert.com/signing/code-signing-certificates#code_signing_key_locker https://www.digicert.com/signing/code-signing-certificates#c...