-
-
Notifications
You must be signed in to change notification settings - Fork 17
Open
Description
During a community meeting we discussed the technology that might be used for staging a release and then releasing it. In this context the use of TUF (The Update Framework) could be very valuable.
TUF allows us to do have delegated roles for signing artifacts. The power of TUF is in the way it establishes a trust root with signing delegations and allowing you to rotate keys if an artifact becomes compromised and should be retracted.
-
Must watch video on TUF and security artifact distribution. https://www.youtube.com/watch?v=lIYXVIPsk_U
-
There is a broad scope in adoption for TUF as a technology.
Using TUF should be an optional choice for providers probably.
Metadata
Metadata
Assignees
Labels
No labels