Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH v2 4/6] app-crypt/openpgp-keys-miniupnp: Package keys used by miniupnp upst
Date: Tue, 06 Oct 2020 18:17:29
Message-Id: robbat2-20201006T180905-590395944Z@orbis-terrarum.net
In Reply to: [gentoo-dev] [PATCH v2 4/6] app-crypt/openpgp-keys-miniupnp: Package keys used by miniupnp upst by "Michał Górny"
1 While I'm absolutely in favour of the overall intent here, I'm not so
2 sure of the design.
3
4 I'm worried about the proliferation of tiny packages just to convey the
5 keys; and how versioning should work if upstream rotates their keys.
6 I picked this message in the thread to respond to, because it was
7 clearest that this could break when the keys are rotated. The old
8 releases might not be verifiable with the new keys.
9
10 Additionally:
11 - not all upstream providers ship .asc files of their keys
12 - some upstreams use signed DIGESTS files rather than directly signing
13 the distfiles (esp. where distfiles are larger)
14
15 Can we instead:
16 Inside the ebuild and/or metadata.xml: convey:
17 1. URL(s) to fetch keys, incl a keyserver support
18 2. Full key fingerprint
19
20 --
21 Robin Hugh Johnson
22 Gentoo Linux: Dev, Infra Lead, Foundation Treasurer
23 E-Mail : robbat2@g.o
24 GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85
25 GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies