1 |
Chris White wrote: |
2 |
> Well, the problem that occurs here is the verification process. With MD5, you |
3 |
> can hit most upstream sites, and they'll have an MD5SUM avaliable that you |
4 |
> can authenticate against. |
5 |
|
6 |
Well if you care enough to verify this, you can easily create an md5sum |
7 |
of the fetched distfile yourself, and compare that with upstream :) |
8 |
Of course, if you want to verify digests of random packages without |
9 |
wanting to actually download and use them, then you would miss MD5 in |
10 |
the manifest, but how likely is that? |
11 |
|
12 |
-- |
13 |
Vlastimil Babka (Caster) |
14 |
Gentoo/Java |
15 |
-- |
16 |
gentoo-dev@g.o mailing list |