docs: add security guidelines for library key verification and metadata
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
After adding new libraries make sure to export the keys for monitoring. Verify that the keys match before using them tho.
|
||||
|
||||
gradlew --write-verification-metadata pgp,sha256 --export-keys
|
||||
Reference in New Issue
Block a user