Wouldn't this have been a nonissue if they were signing updates before? I don't see how someone who got on the box could affect a sigstore signature so long as the signing key wasn't on the box as well
Wouldn't this have been a nonissue if they were signing updates before? I don't see how someone who got on the box could affect a sigstore signature so long as the signing key wasn't on the box as wellIf you have a fediverse account, you can quote this note from your own instance. Search https://fedi.mischivous.com/objects/96147b4f-7f3e-4b5c-a469-0eecc01a7d62 on your instance and quote it. (Note that quoting is not supported in Mastodon.)