torus-cli
torus-cli copied to clipboard
GPG Sign zips, rpms, debs
We should begin Signing the binary distributions posted to https://get.torus.sh, so their origin can be verified
If a user has apt configured such that it relies on trusted repositories it will error when they attempt to install torus from our published repositories!
A work around in the short term for apt is to use the --allow-unauthenticated, this is not ideal. Setting up proper release signing is high on our priority list!