[llvm-dev] Automating the releases a bit better.

Tobias Hieta via llvm-dev llvm-dev at lists.llvm.org
Fri Apr 23 07:29:16 PDT 2021


On Thu, Apr 22, 2021 at 11:46 PM Tom Stellard via llvm-dev
<llvm-dev at lists.llvm.org> wrote:
>
> The easiest option would be to have testers upload binaries directly to the
> GitHub release page.  Is this really any worse from a security perspective
> than what we are doing now?
>
> The main difference is that anyone with commit access can upload releases
> to GitHub whereas with the current sftp uploads, we have to explicitly
> grant people access.
>

Hello Tom,

I didn't really consider this option since it ends up with the
releases not being signed by you / LLVM.org and that more people had
access to upload binaries there. But this is of course an option and
is pretty easy for everyone involved.

-- Tobias


More information about the llvm-dev mailing list