Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adopt sigstore to sign the artifacts #6149

Open
jpkrohling opened this issue Jan 12, 2024 · 2 comments
Open

Adopt sigstore to sign the artifacts #6149

jpkrohling opened this issue Jan 12, 2024 · 2 comments
Labels
Feature Request Suggest an idea for this project

Comments

@jpkrohling
Copy link
Member

Is your feature request related to a problem? Please describe.
We (@open-telemetry/sig-security-maintainers) are evaluating adopting sigstore (including cosign) for signing our artifacts, including the Collector binaries and container images.

I believe you are also signing your artifacts, and I wonder if you'd be willing to consider switching to sigstore, so that we have a project-wide, consistent way to sign our deliverables.

Here's a doc on how it can be used with Gradle, but we'd be more than happy to have a joint call to address questions you may have: https://github.com/sigstore/sigstore-java/tree/main/sigstore-gradle

@jack-berg
Copy link
Member

I'm happy to review contributions by someone else to add this. We are very limited in staffing at the moment and I'm reluctant to add additional review burden by contributing this myself, but I'm glad to review someone else's work.

@cartersocha
Copy link

We’re planning on scheduling some time here in the next month or so. Will follow up with you then @jack-berg

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Feature Request Suggest an idea for this project
Projects
None yet
Development

No branches or pull requests

3 participants