feat: Sign release metadata at production publisher (v2.1.1) - Hash each built artifact and sign the exact Kepr URL, checksum, and provenance envelope with Ed25519 - Read the seed only from PEACH_UPDATE_SIGNING_SEED_HEX and fail closed when it is missing or malformed - Upload only the Base64 signature and cover the path with unit and Kepr integration tests
$ koh steal kepr.uk/koh@c8f1a1923778
·
parent: 7eda2019c028
discussion
log in to leave a comment.