opentelemetry-java
opentelemetry-java copied to clipboard
Sign jar artifacts with sigstore cosign on release
Store them in a zip file attached to the release.
this seems fine to me. Are we waiting for security folks to approve this approach, or should we get this merged for the next release?
I'm going to close this for now until the tooling and maven central have better support for what we're trying to do.