Learn how to leverage HashiCorp Vault and GitHub Actions for code signing workflows to enhance software supply chain security.
Table of contents
» Generating the root CA» Configuring Vault» Issuing Vault’s CA certificate» Running a GitHub pipeline» Verifying a signed script» Why not use a publicly trusted CA?» Next stepsSort: