GithubHelp home page GithubHelp logo

Comments (1)

bdd avatar bdd commented on July 25, 2024

I understand the desire to make the latest artifact fetching less involved but I'd like to stick with artifact names including version information along with os+arch. The reasons are consistency with common practice, and metadata commitment to signed artifact manifests (SHA256 and SHA256.sig).

Don't mean to drop unsolicited operational security advice but I'd highly recommend adding signature1 checking to your artifact fetching automation. Something that'll require a bit scripting on its own, as mentioned in the README.

On the off chance you already have Go in your "build environment", you can use go install bdd.fi/x/runitor/cmd/runitor@latest, to fetch the latest tag, and build locally. Certainly not as small or as ubiquitous tool like curl, and AFAIK cannot verify signed Git tags either.

Footnotes

  1. Runitor release binaries are signed manually by me, offline, after ensuring reproducible build to GH Action built ones from the release tag. The keys listed at https://bdd.fi/x/runitor.pub were all generated on hardware tokens in such a way private keys cannot be exported. The distribution endpoint, hosted on Fly, has discrete credentials to my GH account. Same goes for the domain registrar (Gandi), and the DNS provider (Google).

from runitor.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.