Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.4.0 tarball signature missing #565

Closed
pgajdos opened this issue Sep 23, 2019 · 5 comments
Closed

2.4.0 tarball signature missing #565

pgajdos opened this issue Sep 23, 2019 · 5 comments
Milestone

Comments

@pgajdos
Copy link
Contributor

pgajdos commented Sep 23, 2019

Hello,

thanks for the new release. Do you plan to publish all 'Assets' as in previous releases?

@cary-ilm
Copy link
Member

cary-ilm commented Sep 23, 2019 via email

@pgajdos
Copy link
Contributor Author

pgajdos commented Sep 23, 2019

Explicit tarballs: no real benefit
Signatures: depends also on your view whether we should check we are really using the correct tarball; if you think it is redundant, we will adjust download process for the package

@lgritz
Copy link
Contributor

lgritz commented Sep 23, 2019

I'm pretty sure that the tagged release tarballs you can get from github are signed. There's no reason to think we could either make the tarballs or sign them in any way that's better than what GitHub does automatically for a tagged release, right?

@pgajdos
Copy link
Contributor Author

pgajdos commented Sep 24, 2019

https://wiki.debian.org/Creating%20signed%20GitHub%20releases

Nevertheless, I am not advocating gpg signature implementation, I am just asking whether this change is intentional and therefore I have to change packaging process.

@pgajdos
Copy link
Contributor Author

pgajdos commented Sep 24, 2019

Closing.

@pgajdos pgajdos closed this as completed Sep 24, 2019
@cary-ilm cary-ilm added this to the v2.5.0 milestone Apr 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants