better-docker-ps icon indicating copy to clipboard operation
better-docker-ps copied to clipboard

Signed downloads

Open Decoherent opened this issue 4 months ago • 1 comments

Downloading an executable file from the internet and running it as root is a little unnerving. Would you be willing/interested in having signatures available? Debian's method seems the easiest; they have a checksum file in the assets list with all the files for that version, and just sign the checksum file.

Decoherent avatar Jul 14 '25 18:07 Decoherent

I mean you can simply compile it from source, or use the AUR package :D

But how do you think those signatures would look in practice?
I guess having a checksum file in the github release would be feasible - do you know a project which currently does something similar? For me as a reference.

I can't promise, that this will have a hight priority, but I can look into it.

Mikescher avatar Jul 21 '25 07:07 Mikescher