Skip to content

Security: UAPFormat/UAPF-specification

Security

SECURITY.md

Security and Traceability

UAPF packages MAY be signed and MAY include integrity hashes for auditability.

Recommended:

  • metadata/integrity.yaml with sha256 checksums of cornerstone artifacts
  • Package signing using an organization PKI or signing service

This repository does not mandate a specific signing technology.

There aren't any published security advisories