3proxy/.github
Vladimir Dubrovin db2f57fdd2 Sign packages, publish checksums, attest before upload, narrow permissions
GPG signing of rpm packages and detached signatures for deb packages and
for the SHA256SUMS files, using GPG_PRIVATE_KEY / GPG_PASSPHRASE secrets.
Checksums are published as release assets.

Build provenance is attested before the assets are uploaded, so a failed
attestation does not leave unattested files published.

Workflow permissions are read-only, write permissions are requested per
job only where they are used.
2026-08-21 11:08:20 +03:00
..
workflows Sign packages, publish checksums, attest before upload, narrow permissions 2026-08-21 11:08:20 +03:00
dependabot.yml Add more docker platforms 2026-06-01 20:16:19 +03:00