Skip to main content

Manage signing and release workflows

  • Confirm signing requests use one of the available data-signing algorithms: SHA-256, SHA-384, or SHA-512 combined with RSA, ECDSA, or RSA-PSS; EdDSA (Ed25519).

  • Use the release request/approval workflow (Request release / Approve release) for offline releases, and keep the requesting and approving users separate to preserve separation of duties.

  • Assign signing-only roles (Signer, Build engineer) to automated pipelines and CI/CD service users so that a compromised pipeline credential cannot also approve releases or export keys.