Skip to content

Generate a checksum file for release artifacts and sign it #755

@loicalbertin

Description

@loicalbertin

As: a user
I want to: ensure that downloaded binaries are those that are actually released by the Ystia team
So that: I can be confident in the downloaded binaries (security, integrity, ...)

AC1: Should generate a checksum file that contains checksum for each release artifact
AC2: Should sign the checksum file with a publicly verifiable gpg key

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions