Settings

Theme

GitHub Artifact Attestations

github.blog

7 points by prosim 2 years ago · 1 comment

Reader

woodruffw 2 years ago

I'm personally really excited for this feature: one of the hard lessons around any sort of digital signing is that users do not manage or store their keys correctly, and that poor UX/DX around signing tools (most notably GPG) leads to pervasive normalization of deviance around unsafe practices. Lifting digital signing to the identity later (i.e. by binding it to a digital identity that can be provably controlled, like a GitHub repository) sidesteps nearly all of these problems.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection