Re: Gnome Flatpak build system, descriptions and questions
- From: Shaun McCance <shaunm gnome org>
- To: Michael Catanzaro <mcatanzaro gnome org>, Alexander Larsson <alexl redhat com>, Richard Hughes <hughsient gmail com>
- Cc: "gnome-os-list gnome org" <gnome-os-list gnome org>, desktop-devel-list <desktop-devel-list gnome org>
- Subject: Re: Gnome Flatpak build system, descriptions and questions
- Date: Fri, 26 Aug 2016 11:48:58 -0400
On Fri, 2016-08-26 at 10:17 -0500, Michael Catanzaro wrote:
On Fri, 2016-08-26 at 10:29 -0400, Shaun McCance wrote:
Don't all maintainers already use signed tags for releases?
No. I used to do this, but stopped a couple years ago because it was
pointless. Nobody should trust my key, so why use it?
IIRC, git.gnome.org won't let you push an unsigned tag. I've been
tagging releases since the days of CVS, because tags are useful. I
thought everybody did.
That still leaves the question: If the release team tags with a key we
can all trust, how does the release team trust that the commit they
tagged is the one the maintainer intended?
--
Shaun
[
Date Prev][
Date Next] [
Thread Prev][
Thread Next]
[
Thread Index]
[
Date Index]
[
Author Index]