Skip to content

Dpm SIgned Artifacts #303

Description

@dasormeter

Goals

Sign all artifacts published by dpm, including components, dars and the bundle

Background

Industry best practice guidance is that we sign artifacts that we author to prove provenance.

Signing should be possible for each released artifact to OCI, potentially

  • At component / docker image / helm chart / (and soon dar) level
  • At bundled tarball level for installation bundles

There is some signing prior art in the 2.x world, but it has been spottily implemented for 3.x

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions