Signed manifests and code provenance #12

Open
opened 2026-09-25 15:31:14 +02:00 by morten-olsen · 0 comments
Owner

Integrity hashes protect chunks, but the manifest itself is unauthenticated beyond TLS.

Done when: manifests are signed, runtimes verify them, and pinning to a known key is possible.

Integrity hashes protect chunks, but the manifest itself is unauthenticated beyond TLS. **Done when:** manifests are signed, runtimes verify them, and pinning to a known key is possible.
Sign in to join this conversation.
No description provided.