Hacker News new | past | comments | ask | show | jobs | submit login

It would be nice if the release process also added the hash of any built binaries to a distributed append-only log. That's sort of the approach that sigstore and rekor were made for, to enable Binary Transparency, and they're already being used in the Arch Linux package ecosystem:

https://github.com/kpcyrd/pacman-bintrans




this is definitely on our radar! We didn't do any major work on artifacts / assets as part of this effort but there are a bunch of backlogged items, including individual hashes, that we would like to do in the future.


I'm interested in talking about this. Could you email me at my work address (in my profile)?


Might make the most sense to kick off a thread in https://github.com/github/feedback/discussions/5962 so we can have a broader conversation




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: