Skip to content

GPG sign gitea releases on the gitea.io download page #1001

@vishnunaini

Description

@vishnunaini
  • Gitea version (or commit ref): 1.0.2
  • Git version: 2.11.0
  • Operating system: All
  • Database (use [x]):
    • PostgreSQL
    • MySQL
    • SQLite
  • Can you reproduce the bug at https://try.gitea.io:
    • Yes (provide example URL)
    • No
    • Not relevant
  • Log gist: NA

Description

The title says it all. Please maintain a GPG master key with the team's trusted members and sign all gitea releases with this master keys to maintain a chain of trust. HTTPS on the download page is not enough as that is vulnerable to the case where gitea.io can be compromised.

Screenshots

NA

Metadata

Metadata

Assignees

No one assigned

    Labels

    type/questionIssue needs no code to be fixed, only a description on how to fix it yourself.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions