Skip to content

Tracking: Trust model for signed Rust / Rustup releases #2029

@kinnison

Description

@kinnison

Once we have simplistic signature checking in place (#2028) we need to decide upon and deploy a more comprehensive trust model so that we're not doing the bare minimum to protect our users.

  • Meeting between relevant parties (e.g. Sequoia-PGP team, Infra team, Rustup team, and DKG) to kick off a working group
  • That working group to discuss and come up with a functional trust model which improves on the status quo
  • Implementation of that trust model in rustup.

People who might be relevant to this are:

Obviously we will not limit the wg to those, but that's a starting point.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels
    No fields configured for Tracking Issue.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions