Skip to content

Sign releases with cosign keyless #1

Description

@aardbol

Is your feature request related to a problem?

No

Describe the solution you'd like

Makes it easier to verify release integrity and maintain packages automatically like https://aur.archlinux.org/packages/mercurygram-desktop-bin

example: https://github.com/Picocrypt-NG/Picocrypt-NG/blob/main/.github/actions/sign-and-attest/action.yml

Describe alternatives you've considered

SHA hash verification

Additional context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions