Global Feed Post Login
Replying to Avatar sommerfeld

I download the tarballs locally on my laptop, compute checksums into manifest file and gpg sign the manifest file. Then I upload the manifest and signature asc file to the release.

https://github.com/sommerfelddev/sentrum/blob/master/utils/create-signed-manifest.sh

No way I would give github my pgp key lol.

Avatar
franzap 1y ago

Good to know you do that, so many devs just stuff it in the GH secrets

Reply to this note

Please Login to reply.

Discussion

No replies yet.