Skip to content

Conversation

@xnox
Copy link
Member

@xnox xnox commented Dec 3, 2025

This adds a universal chianguard enforce commit signing config. This
supports all keyless and github verified signing methods, and covers
all humans and trusted robots.

Such config is universal, and will continue to work across repository
renames and moves.

If desired, the config can be locked down further but so far we
haven't managed to make enforce a required check but hopefully such
wide policy can actually be ratcheted to be made required as any and
all signing methods are supported and trusted.

@xnox xnox force-pushed the chainguard-enforce-config-template branch 2 times, most recently from d6004f7 to f215810 Compare December 3, 2025 14:09
@xnox xnox requested review from a team December 3, 2025 14:18
This adds a universal chianguard enforce commit signing config. This
supports all keyless and github verified signing methods, and covers
all humans and trusted robots.

Such config is universal, and will continue to work across repository
renames and moves.

If desired, the config can be locked down further but so far we
haven't managed to make enforce a required check but hopefully such
wide policy can actually be ratcheted to be made required as any and
all signing methods are supported and trusted.
@xnox xnox force-pushed the chainguard-enforce-config-template branch from f215810 to 7fa5364 Compare December 3, 2025 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant