Gentoo Archives: gentoo-project

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-project@l.g.o, Alec Warner <antarus@g.o>
Subject: Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust
Date: Thu, 31 Jan 2019 22:02:33
Message-Id: c1d955d8-c444-cac5-553c-3b247b7483c8@gentoo.org
In Reply to: Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust by Alec Warner
1 On 1/31/19 10:40 PM, Alec Warner wrote:
2 >> In addition comes a better certainty about the UID used for copyright in
3 >> signed-off-by, we as a distribution rely on this for both developers and
4 >> external contributors, and we need to demonstrate that we have taken
5 >> reasonable measures to ensure that what we add is unencumbered.
6 >>
7 > I assume this is where the mandatory bits come in (and obviously where all
8 > of the exciting politicking will happen around who owns how to assess and
9 > address risk to "gentoo" and what "gentoo" is and so forth.)
10 >
11 > To that end, is the WoT also mandatory for contributors? I didn't see
12 > anything in the GLEP about it.
13
14 It would certainly be interesting to discuss whether it makes sense to
15 require contributors to be part of the strong set, indeed.
16
17 --
18 Kristian Fiskerstrand
19 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
20 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature