GPG-signed releases and reproducible builds #10

Open
opened 2026-04-07 17:25:32 -04:00 by commander · 0 comments
Owner

All ISO releases should be GPG-signed with a project signing key for supply chain integrity.

  • Generate Alfred Linux GPG signing key (4096-bit RSA or Ed25519)
  • Publish public key on alfredlinux.com and key servers
  • Sign every ISO release (.iso.asc detached signature)
  • Add signature verification to download page
  • Document verification: gpg --verify alfred-linux.iso.asc
  • Investigate reproducible build pipeline
All ISO releases should be GPG-signed with a project signing key for supply chain integrity. - [ ] Generate Alfred Linux GPG signing key (4096-bit RSA or Ed25519) - [ ] Publish public key on alfredlinux.com and key servers - [ ] Sign every ISO release (.iso.asc detached signature) - [ ] Add signature verification to download page - [ ] Document verification: gpg --verify alfred-linux.iso.asc - [ ] Investigate reproducible build pipeline
Sign in to join this conversation.
No Label
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: commander/alfred-linux#10
No description provided.