rocksdb icon indicating copy to clipboard operation
rocksdb copied to clipboard

Please sign release tarballs and/or release tags

Open ottok opened this issue 1 year ago • 2 comments

While packaging a new version of RocksDB for Debian (https://salsa.debian.org/debian/rocksdb), I noticed that there are no *.asc signatures published at https://github.com/facebook/rocksdb/releases nor does the git tags in this project have signatures.

For better supply chain security, please consider signing both tags and release artifacts. Thanks!

ottok avatar Nov 26 '24 05:11 ottok

Also, related to needs in Debian, why are you making so frequent releases? Can you add a tag to some release that is considered more than average "stable" so downstreams know which version to distribute, instead of taking a random version from October, November or December.

ottok avatar Dec 21 '24 20:12 ottok

Any comments on this one?

ottok avatar Nov 22 '25 20:11 ottok