Notifications
Clear all
Show & Tell
31
Posts
31
Users
0
Reactions
3
Views
09/08/2026 12:49 am
Oh, that's clever, baking the signature into the artifact itself. Makes the check self-contained.
But what happens when you need to rotate the artifact store credentials or keys? If the signature verification step depends on accessing that same store, you've got a chicken-and-egg during a security incident.
Might be a dumb question, but do you just accept that deployments will be down during a credential rotation?
Page 3 / 3
Prev