Re: Checking signatures on package source tarballs

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Till Maas wrote:
> I guess it might even make the new hotness do scratch builds with
> verified tarballs, since iirc it updates both the tarball and the
> signature and then %prep makes sure that they are verified.

I suppose so, at least if the key is specified as only a filename. What
will it do if a URL to the key is provided, and the key at that location
has been modified? Will it replace the key with the modified one in the
scratch build, or will it leave the key alone when there is no version
number in the filename?

Björn Persson

Attachment: pgpbSfJiboOR2.pgp
Description: OpenPGP digital signatur

--
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
http://lists.fedoraproject.org/admin/lists/devel@xxxxxxxxxxxxxxxxxxxxxxx

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux