Security
Release signing
How releases are signed and verified.
What this page will cover
- How packages are signed and which key signs them
- Verifying a download before installing it
- The SBOM published with each release
- Key rotation and revocation
Why it is not here yet
No packages are published yet, so there is nothing to verify.
Follow the build
The roadmap shows what is specified, what is being built and what is still only planned.
View the roadmapContribute
Drivers, integrations, translations and documentation are all places to start.
How to contributeReport a security issue
Responsible disclosure, with a stated response commitment.
Disclosure policy