@nerds
I'm creating reproducible builds for Amber. I have a functioning github workflow, but the dev said he didn't want to put his gpg keys into github, so im looking for advixe on work arounds.
I think he is worried about the key being compromised, but that key should be rotated regardless of where its stored, correct? It could be stored in aws secrets manager and then jit access can be provided to the runner. Ultimately, the actual signing and upload of the manifest could be done locally then uploaded, right? That shouldn't affect reproducibility because the apks should have no ksecret material so verification is separate from reproducibility, right?
Any thoughts are appreciated, I'm trying to get a cookie cutter process to add these as attestations in
@Zapstore so we can have more features than fdroid. #asknostr