Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

CII Silver and Gold badges require all release artifacts be cryptographically signed [signed_releases].

The project MUST cryptographically sign releases of the project results intended for widespread use, and there MUST be a documented process explaining to users how they can obtain the public signing keys and verify the signature(s). The private key for these signature(s) MUST NOT be on site(s) used to directly distribute the software to the public.

...