Description
Consider Signing tags of releases
Proposed solution
As the package maintainer of Arch Linux I would appreciate if you could help maintaining the chain of trust with PGP signatures on commits/tags. This can be handled from the Arch Linux build tools and can automatically validate PGP public key of the author of the commit/tag.
Tasks:
- Sign commits and tags of releases
- Mention the public keys used for signing the above in README or any other file within the repository so downstream systems can validate independently.
- Add any new maintainers who can release on the above list
Describe alternatives you've considered
N/A
Additional context
N/A
Description
Consider Signing tags of releases
Proposed solution
As the package maintainer of Arch Linux I would appreciate if you could help maintaining the chain of trust with PGP signatures on commits/tags. This can be handled from the Arch Linux build tools and can automatically validate PGP public key of the author of the commit/tag.
Tasks:
Describe alternatives you've considered
N/A
Additional context
N/A