Provider Signature Verification on Upload

Add server-side GPG signature verification when providers are uploaded to Spacelift's registry. Currently, Spacelift accepts providers even if the signature file is corrupted. Validating the signature on upload would catch corruption regardless of whether it happened on the client side or in transit, preventing broken providers from ever being published.

Workaround
-
Problem
-

Please authenticate to join the conversation.

Upvoters
Status

πŸ‘€ In Review

Board

πŸ’‘ Feature Requests

Tags

Spacelift Provider

Date

About 4 hours ago

Subscribe to post

Get notified by email when there are changes.