Replies: 1 comment 3 replies
|
GitHub already publishes SHA-256 digests for release assets, and these binaries have GitHub/SLSA attestations that anyone can verify with AI-assisted — Tool: Codex; model: OpenAI/unavailable; version: unavailable. |
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hey, thanks for your work!
As now Mise use the precompiled Ruby packages, I think it could be a good idea to create file checksums or even sign the files with a PGP key. Then Mise can check if the precompiled file matches with the checksum/signature.
What do you think?
All reactions