Skip to content

Code-sign and attest community release artifacts across platforms #41

@Shreyas582

Description

@Shreyas582

Scope

Harden community release trust by adding artifact signing and verification guidance across supported platforms.

Acceptance Criteria

  • Windows release artifacts are code-signed (or documented as unsigned with explicit roadmap/controls if cert unavailable).
  • macOS release artifacts include signing/notarization status and validation steps.
  • Linux artifacts include signature/attestation strategy with documented verification flow.
  • Release workflow publishes verification metadata alongside SHA256SUMS and SBOM.
  • Security/release docs updated with operator verification steps.

Metadata

Metadata

Assignees

No one assigned

    Labels

    milestone:v1.0.0Tracking label for v1.0.0 roadmap workpriority:p1High-priority issue for current milestonereleaseRelease planning or publication taskssecuritySecurity-related hardening or fixes

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions