Gentoo Archives: gentoo-dev

From: Mike Frysinger <vapier@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: rsync mirror security
Date: Tue, 11 Aug 2015 03:07:04
Message-Id: 20150811030654.GA9481@vapier
In Reply to: [gentoo-dev] Re: rsync mirror security by Matthias Maier
1 On 10 Aug 2015 16:05, Matthias Maier wrote:
2 > > Users can fetch/pull from Github.
3 >
4 > We could also provide automatic signed tags every 30min/1h/2h/whatever
5 > (signed with a suitable infrastructure key). With that, the integrity of
6 > a tagged git checkout can be easily verified on client side.
7
8 it would have to re-use the same tag name every time otherwise we end up with
9 17.5k/8.7k/4.3k/whatever new tags per year ... a really bad idea
10
11 depending on how fast the process is, it could just be part of the receive hook
12 on the server that does the checking now. that way the tag is always up to date
13 with every push a developer makes.
14 -mike

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] Re: rsync mirror security Kent Fredric <kentfredric@×××××.com>
Re: [gentoo-dev] Re: rsync mirror security Matthias Maier <tamiko@g.o>