[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH] package.el: check tarball signature

From: Stefan Monnier
Subject: Re: [PATCH] package.el: check tarball signature
Date: Wed, 02 Oct 2013 23:51:30 -0400
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3.50 (gnu/linux)

DU> I'm fine with signing with dput for Debian and gnupload for GNU, who
DU> else of you really wants that feature.  Reference?

I don't want that feature in package.el where it does not belong.
If someone wants it in package-x.el, that's fine, of course.

> If we move to a branch-pull request-merge model, this will be much less
> important since the signing will happen at the time of the merge on the
> server; the reviewer never needs to manually sign anything.  But at
> least for now we need interactive tools to automate that process and
> gnupload would certainly fill that need.  So please don't dwell on this.

Much too hypothetical for me.  If/when we start supporting signatures
provided by the author, we'll try and figure out how that can work
(which is not obvious at all, since the signature should be applied to
the tarball, but the tarball is generated later on by a batch process).


reply via email to

[Prev in Thread] Current Thread [Next in Thread]