summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-dev/2012-January/011222.html
blob: b3bf81460230c18b394becb16f0de79c60e61ca7 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
 <HEAD>
   <TITLE> [Mageia-dev] Signature verification of sources
   </TITLE>
   <LINK REL="Index" HREF="index.html" >
   <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Signature%20verification%20of%20sources&In-Reply-To=%3C201201110958.53575.bgmilne%40staff.telkomsa.net%3E">
   <META NAME="robots" CONTENT="index,nofollow">
   <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
   <LINK REL="Previous"  HREF="011212.html">
   <LINK REL="Next"  HREF="011210.html">
 </HEAD>
 <BODY BGCOLOR="#ffffff">
   <H1>[Mageia-dev] Signature verification of sources</H1>
    <B>Buchan Milne</B> 
    <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Signature%20verification%20of%20sources&In-Reply-To=%3C201201110958.53575.bgmilne%40staff.telkomsa.net%3E"
       TITLE="[Mageia-dev] Signature verification of sources">bgmilne at staff.telkomsa.net
       </A><BR>
    <I>Wed Jan 11 08:58:53 CET 2012</I>
    <P><UL>
        <LI>Previous message: <A HREF="011212.html">[Mageia-dev] Signature verification of sources
</A></li>
        <LI>Next message: <A HREF="011210.html">[Mageia-dev] Display manager
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#11222">[ date ]</a>
              <a href="thread.html#11222">[ thread ]</a>
              <a href="subject.html#11222">[ subject ]</a>
              <a href="author.html#11222">[ author ]</a>
         </LI>
       </UL>
    <HR>  
<!--beginarticle-->
<PRE>On Tuesday, 10 January 2012 22:23:25 P. Christeas wrote:
&gt;<i> On Tuesday 10 January 2012, Buchan Milne wrote:
</I>&gt;<i> &gt; I think we should be in the position to be able to verify the origin of
</I>&gt;<i> &gt; any software we provide to users.
</I>&gt;<i> &gt; ...
</I>&gt;<i> 
</I>&gt;<i> Just a reminder: a git-based build process would implicitly cover that
</I>&gt;<i> aspect, since the comit SHAs would be traceable back to the code
</I>&gt;<i> maintainers.
</I>
As far as I understand, it wouldn't necessarily provide a guarantee that the 
upstream git was compromised before it was cloned by the package maintainer.

Regards,
Buchan
</PRE>




























































































<!--endarticle-->
    <HR>
    <P><UL>
        <!--threads-->
	<LI>Previous message: <A HREF="011212.html">[Mageia-dev] Signature verification of sources
</A></li>
	<LI>Next message: <A HREF="011210.html">[Mageia-dev] Display manager
</A></li>
         <LI> <B>Messages sorted by:</B> 
              <a href="date.html#11222">[ date ]</a>
              <a href="thread.html#11222">[ thread ]</a>
              <a href="subject.html#11222">[ subject ]</a>
              <a href="author.html#11222">[ author ]</a>
         </LI>
       </UL>

<hr>
<a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev
mailing list</a><br>
</body></html>