Skip to content

TEA release staging and releasing #184

@matglas

Description

@matglas

During a community meeting we discussed the technology that might be used for staging a release and then releasing it. In this context the use of TUF (The Update Framework) could be very valuable.

TUF allows us to do have delegated roles for signing artifacts. The power of TUF is in the way it establishes a trust root with signing delegations and allowing you to rotate keys if an artifact becomes compromised and should be retracted.

Using TUF should be an optional choice for providers probably.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions