Signed tags for future petitboot releases

Joel Stanley joel at jms.id.au
Wed Feb 5 10:53:21 AEDT 2020


Hey Jeremy,

Are you able to create signed tags for the petitboot releases you make?

When you do so, and your key is known by github, we get a nice little
Verified box next to the tag in the github UI. You can see this next
to previous tags:

 https://github.com/open-power/petitboot/releases

More importantly, someone is able to check that someone in possession
of your key created the tag.

Cheers,

Joel


More information about the Petitboot mailing list