Skip to content

[feature] Enable immutable releases #4459

@HastD

Description

@HastD

GitHub now supports immutable releases, which prevents tags associated with a release from being changed or removed after publication.

Enabling this feature for this repository and making a new release (to create an immutable tag) would improve supply-chain security and substantially mitigate the impact of slsa-framework/slsa-verifier#12: an immutable tag, like a hash, is pinned to a specific commit and can't be modified after publication, while not having the problems associated with referencing an SLSA generator by a hash.

Metadata

Metadata

Assignees

No one assigned

    Labels

    status:triageIssue that has not been triagedtype:featureNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions