Let users authenticate your Github Releases (and more)
The days of deploying an infrastructure using only Linux distributions’ packages are long gone. Software is now downloaded from Github releases, used to build docker images, piping a shell script to a shell. All this often happens without any authentication of any form, creating security risks. Asfaload fixes these risks.
Define custom multisignature requirements (m-of-n) for different levels of assurance.
Apply multisignature sign-off to software deployments, container images, file downloads, and more.
All sign-off records are stored in a repository and the sign-off history can be consulted.
You don't need to register an account or provide personal information. Your keypair is your identity.
Chooses technologies viable for the long term, incl. support for git's sha256 oid.
Integrate Asfaload into your existing workflows and pipelines with minimal disruption.
Sign-offs can be provided by human operators or automated software agents (e.g., security scanners).
Available for on-premise deployments
The Asfaload software is developed under an open source license, with possibility of a commecial license