How to verify provenance of MS Store releases #1110
Replies: 2 comments
-
|
Hi, |
Beta Was this translation helpful? Give feedback.
-
|
Understood, thanks! |
Beta Was this translation helpful? Give feedback.
-
|
Hi, |
Beta Was this translation helpful? Give feedback.
-
|
Understood, thanks! |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I appreciate the supply chain security considerations put in place for AppControl Manager, so that the release artifact attestations can be used to validate the msixbundle published on GitHub. But, I'm hoping to understand how I can attest in the same way with regards to the releases published to the Microsoft Store?
It seems my options are: use the unsigned, but attested release or the signed, but un-attestable release (and I need to self-sign if I want the former)? Curious for your thoughts/suggestions, thanks!
Beta Was this translation helpful? Give feedback.
All reactions