You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For software supply chain security, I'd like to be able to verify that the binary I curl-ed is the same binary that Google intended me to curl. Shasums seem like the normal way of achieving this.
The text was updated successfully, but these errors were encountered:
Expected behavior
When I visit https://github.com/GoogleContainerTools/skaffold/releases, I would like to be able to download or review officially generated sha 256 sums of binaries.
Actual behavior
No such shasums are currently published.
Information
The installation instruction for skaffold is:
For software supply chain security, I'd like to be able to verify that the binary I curl-ed is the same binary that Google intended me to curl. Shasums seem like the normal way of achieving this.
The text was updated successfully, but these errors were encountered: