Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

cd: re-enable release signing

未關閉
#1,966 6 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 10 天內回覆

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
42/100
Issue 類型
功能
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
github-actions, python

研究方向

從 PR 1946 引入的 CD 工作流程和 RELEASE.md 中的發布說明開始;將它們與安裝文件的 verify-release-signatures 區段進行比較。檢視 verify_release 指令碼,將其作為可能的整合點,然後確定哪種簽署方式已獲核准。當發布成品包含簽署說明,且簽署已整合至發布流程中時,即視為完成。

由索引模型根據 Issue 內容生成。

描述

Description of issue or feature request:
https://github.com/theupdateframework/python-tuf/pull/1946 adds a CD workflow to release build artifacts on PyPI and GH upon successful completion of the CI workflow for a pushed release tag.

The PR also removes instructions from RELEASE.md to gpg sign release artifacts and add them to the GitHub release assets as part of the previously manual release process. However, the installation docs still mention release signatures.

Current behavior:
No instructions / release process integration to sign release artifacts

Expected behavior:
Add instructions to sign release artifacts and integrate with release process

Ideas:

主要語言
Python
星號
1.7k
分支
304
平均合併
9 小時 25 分鐘
30 天內合併 PR
14

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

theupdateframework/python-tuf 的其他 Issue

查看 theupdateframework/python-tuf 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。