TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

How to Outsource App Signing?

3 点作者 lucasgonze超过 5 年前
We have a desktop Electron app which needs to be signed before we ship it. Most of this codebase is written by developers on Upwork. Doing the work to sign the app means putting our private key in their hands. To give the key to a developer we hardly know make no sense from a security point of view.<p>That&#x27;s not even the end of it. To do signing in our CI&#x2F;CD process, we have to put the private key in there, which makes it available to anybody we ever hire in the future.<p>How can security work like this be outsourced? Is there some trick, like keeping the real private key on the CI&#x2F;CD server?<p>(Background #1: we&#x27;re a small company funded on revenues, and we mind spending very carefully. Background #2: the CI&#x2F;CD server is on Gitlab).

暂无评论

暂无评论