Update README.md

This commit is contained in:
Max Goedjen 2025-08-23 15:04:34 -07:00 committed by GitHub
parent 2355d3f989
commit d70a9b8303
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -49,7 +49,10 @@ There's a [FAQ here](FAQ.md).
### Auditable Build Process ### Auditable Build Process
Builds are produced by GitHub Actions with an auditable build and release generation process. Each build has a "Document SHAs" step, which will output SHA checksums for the build produced by the GitHub Action, so you can verify that the source code for a given build corresponds to any given release. Builds are produced by GitHub Actions with an auditable build and release generation process.
#### Attestated Releases
Starting with Secretive 3.0, builds are attestd using [GitHub Artifact Attestation](https://docs.github.com/en/actions/concepts/security/artifact-attestations).
### A Note Around Code Signing and Keychains ### A Note Around Code Signing and Keychains