From 1be510f9529cb082f802408b472a77d074b394c0 Mon Sep 17 00:00:00 2001 From: Nicolas Vigier Date: Sun, 14 Apr 2013 13:46:12 +0000 Subject: Add zarb MLs html archives --- zarb-ml/mageia-dev/2012-January/011222.html | 161 ++++++++++++++++++++++++++++ 1 file changed, 161 insertions(+) create mode 100644 zarb-ml/mageia-dev/2012-January/011222.html (limited to 'zarb-ml/mageia-dev/2012-January/011222.html') diff --git a/zarb-ml/mageia-dev/2012-January/011222.html b/zarb-ml/mageia-dev/2012-January/011222.html new file mode 100644 index 000000000..b3bf81460 --- /dev/null +++ b/zarb-ml/mageia-dev/2012-January/011222.html @@ -0,0 +1,161 @@ + + + + [Mageia-dev] Signature verification of sources + + + + + + + + + +

[Mageia-dev] Signature verification of sources

+ Buchan Milne + bgmilne at staff.telkomsa.net +
+ Wed Jan 11 08:58:53 CET 2012 +

+
+ +
On Tuesday, 10 January 2012 22:23:25 P. Christeas wrote:
+> On Tuesday 10 January 2012, Buchan Milne wrote:
+> > I think we should be in the position to be able to verify the origin of
+> > any software we provide to users.
+> > ...
+> 
+> Just a reminder: a git-based build process would implicitly cover that
+> aspect, since the comit SHAs would be traceable back to the code
+> maintainers.
+
+As far as I understand, it wouldn't necessarily provide a guarantee that the 
+upstream git was compromised before it was cloned by the package maintainer.
+
+Regards,
+Buchan
+
+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+

+ +
+More information about the Mageia-dev +mailing list
+ -- cgit v1.2.1