Gentoo Archives: gentoo-dev

From: Ulrich Mueller <ulm@g.o>
To: "Michał Górny" <mgorny@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH 1/5] verify-sig.eclass: New eclass to verify OpenPGP sigs
Date: Tue, 06 Oct 2020 11:17:13
Message-Id: u1ribob7y@gentoo.org
In Reply to: [gentoo-dev] [PATCH 1/5] verify-sig.eclass: New eclass to verify OpenPGP sigs by "Michał Górny"
1 >>>>> On Tue, 06 Oct 2020, Michał Górny wrote:
2
3 > verify-sig eclass provides a streamlined approach to verifying upstream
4 > signatures on distfiles. Its primary purpose is to permit developers
5 > to easily verify signatures while bumping packages. The eclass removes
6 > the risk of developer forgetting to perform the verification,
7 > or performing it incorrectly, e.g. due to additional keys in the local
8 > keyring. It also permits users to verify the developer's work.
9
10 We've already discussed it in #-qa, and I still think that this is
11 over-engineered. Users can validate the distfile by the Manifest and its
12 signature, so exposing the feature to users is redundant.
13
14 Ulrich

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] [PATCH 1/5] verify-sig.eclass: New eclass to verify OpenPGP sigs "Frédéric Pierret" <frederic.pierret@××××××××.org>