mirror of
https://github.com/3proxy/3proxy.git
synced 2026-08-26 09:55:48 +08:00
GPG signing of rpm packages and detached signatures for deb packages and for the SHA256SUMS files, using GPG_PRIVATE_KEY / GPG_PASSPHRASE secrets. Checksums are published as release assets. Build provenance is attested before the assets are uploaded, so a failed attestation does not leave unattested files published. Workflow permissions are read-only, write permissions are requested per job only where they are used. |
||
|---|---|---|
| .. | ||
| workflows | ||
| dependabot.yml | ||