[Packaging Pipeline] Securely sign packages hosted on Drupal.org using the TUF framework and Rugged

Created on 2 December 2022, over 2 years ago
Updated 21 March 2023, about 2 years ago

Problem/Motivation

As part of the major initiatives to support Automatic Updates → and the Project Browser → , the Drupal.org infrastructure team has prioritized a major security enhancement - securely signing packages using Rugged, an implementation of TUF, theupdateframework.io.

Proposed resolution

An RFP → for implementing a secure server side signing method according to the tough specification was released in June of 2021.

Consensus Enterprises → was selected as the implementation partner for this system, working together with the Drupal Association on the implementation details. The Drupal Association is working with infrastructure management partners Tag1 Consulting → to stand up this infrastructure in the cloud, so it can be integrated into the packaging pipeline.

Remaining tasks

  • - started
  • Current work in rugged:
  • Next deployment evaluation
  • Integration testing with AutoUpdates/Project Browser teams
  • Security audit/penetration testing (as resources are available)
🌱 Plan
Status

Active

Component

Packaging

Created by

🇺🇸United States hestenet Portland, OR 🇺🇸

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024