Currently we use sigstore to sign our releases. There is a github action that goes a step further and more conveniently stores this in a more verifiable way on GH: https://github.com/actions/attest-build-provenance. I think we should add this as a build attestation proess.
Currently we use sigstore to sign our releases. There is a github action that goes a step further and more conveniently stores this in a more verifiable way on GH: https://github.com/actions/attest-build-provenance. I think we should add this as a build attestation proess.