1 |
On Fri, Sep 18, 2015 at 5:16 AM, Kristian Fiskerstrand <k_f@g.o> wrote: |
2 |
> I do sincerely hope package maintainers |
3 |
> have a well thought out setup for key management locally and in fact |
4 |
> verify the OpenPGP signatures vs known good keys, and that appropriate |
5 |
> measures are being taken in the case of non-maintainer commits that |
6 |
> doesn't reduce the level of security. |
7 |
|
8 |
I'd be utterly shocked if even 30% of maintainers are checking |
9 |
upstream gpg keys when doing new releases. I'm sure it happens |
10 |
sometimes. |
11 |
|
12 |
I'd suggest adding it to the DCO when we actually have a DCO, though |
13 |
that doesn't actually ensure that anybody follows it. And the wording |
14 |
would have to be careful since not all upstreams even sign their |
15 |
releases at all, and if they do many/most maintainers probably haven't |
16 |
personally verified the keys. I certainly haven't met the upstream |
17 |
developers of any of the packages I maintain in-person - I haven't |
18 |
even met another Gentoo dev in-person. |
19 |
|
20 |
-- |
21 |
Rich |