[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[GMG-Devel] please use signed git tags
From: |
Thomas Koch |
Subject: |
[GMG-Devel] please use signed git tags |
Date: |
Mon, 11 Mar 2013 21:02:44 +0100 |
User-agent: |
KMail/1.13.7 (Linux/3.8-trunk-amd64; KDE/4.8.4; x86_64; ; ) |
Hi,
as long as mediagoblin is not packaged in Debian and I need to install it from
Git you could really improve the situation by using signed git tags, via
git tag -s
Thus I could be sure, that I cloned the correct code and not a modified
version. If you wonder whether signing code and artefacts is necessary, please
have look here:
http://www.koch.ro/blog/index.php?/archives/153-On-distributing-binaries.html
It might also be good to use signed commits (since Git 1.7.?), but I don't
have experience with those myself.
Regards,
Thomas Koch, http://www.koch.ro
- [GMG-Devel] please use signed git tags,
Thomas Koch <=