You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It would be nice to have .signature files added to the Github releases. How it stands at most we can only verify we're downloading from Github and not some man in the middle. We cannot verify that the repo has not been compromised by some third party releasing compromised software. Signing the release files with your own key would prove a trusted authority released the software.
The text was updated successfully, but these errors were encountered:
It would be nice to have
.signature
files added to the Github releases. How it stands at most we can only verify we're downloading from Github and not some man in the middle. We cannot verify that the repo has not been compromised by some third party releasing compromised software. Signing the release files with your own key would prove a trusted authority released the software.The text was updated successfully, but these errors were encountered: