Replies: 4 comments
|
As a user, I want to be able to query or track which packages have been signed by which keys Covers:
|
0 replies
|
As a user, I would like to be able to attest / enforce that all packages in repo X are signed by a trusted key Questions:
Covers:
|
0 replies
|
As a user, I would like to verify package signatures of incoming packages against known public keys Questions:
Covers:
|
0 replies
|
As a user, I would like to be able to inspect some information about the keys (algorithm, fingerprint, key ID, signature version) Questions:
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
This thread is for a discussion about different use cases around tracking, management and enforcement of package signatures
All reactions