Skip to content

Sigstore Integration #300

@ChrissW-R1

Description

@ChrissW-R1

To further improve supply chain security and provide an additional modern trust mechanism beside GPG signatures, trusted timestamps, and in-toto attestations, the project should integrate the Sigstore Maven Plugin into the Maven build process.

Goal

Automatically sign produced Maven artifacts during release builds using Sigstore keyless signing via GitHub Actions OIDC identity.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestsecurityNon-sensitive vulnerabilities

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions