Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verifying sources and/or binaries #16

Open
Gigadoc2 opened this issue Feb 4, 2020 · 3 comments
Open

Verifying sources and/or binaries #16

Gigadoc2 opened this issue Feb 4, 2020 · 3 comments

Comments

@Gigadoc2
Copy link

Gigadoc2 commented Feb 4, 2020

It seems that you currently do not sign the git tags or the published binary.
To enable (semi-)automatic updates of prosody-filer in production, it would be nice to have some way to automatically verify that the sources used to build the binary or the downloaded binary itself is indeed still coming from you ;)

@ThomasLeister
Copy link
Owner

ThomasLeister commented Feb 4, 2020 via email

@ghost
Copy link

ghost commented Feb 20, 2020

+1 for apt repository! :)

@ThomasLeister
Copy link
Owner

Latest commits make use of signed commits, now. I don't consider this a full solution to your wish, but it might be a first step. I'd be happy to offer you an apt repository, soon. There have been experiments already, but I don't feel confident enogh for the package maintainer / repo maintainer role, yet. So don't expect an APT repo, too soon ;)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants