Skip to content

Create release signing key policy #1905

@quarckster

Description

@quarckster

Gpg signature is a crucial component of our release artifacts but we don't have any policy for release signing key where would described who can access it, what the format is, rotation period, what should be in case of leaking.

Acceptance criteria

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

To do

Status

Pre-Refinement

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions