Skip to content

Tracking: Trust model for signed Rust / Rustup releases #2029

Description

@kinnison

Once we have simplistic signature checking in place (#2028) we need to decide upon and deploy a more comprehensive trust model so that we're not doing the bare minimum to protect our users.

  • Meeting between relevant parties (e.g. Sequoia-PGP team, Infra team, Rustup team, and DKG) to kick off a working group
  • That working group to discuss and come up with a functional trust model which improves on the status quo
  • Implementation of that trust model in rustup.

People who might be relevant to this are:

Obviously we will not limit the wg to those, but that's a starting point.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions