On fre, 2016-08-26 at 05:02 -0500, Michael Catanzaro wrote:
Clone via https:// rather than using git://

Does git verify signatures for this? That avoids the MITM attack i

Still, I would like us to eventually have a setup where every stable
release of every gnome module has a GPG signed commit, put there by the
release team. Then we could make sure that the binaries for stable
builds are the proper releases.

