On Sat, Mar 30, 2024 at 11:47 AM Miroslav Suchý <msuchy@xxxxxxxxxx> wrote: > > Dne 30. 03. 24 v 1:25 odp. Chris Adams napsal(a): > > Using a signed tarball is ideally better than a git tag (it's an extra > level of author attestation). > > In this case signed tarball would not help at all. And git-tag would prevent this attack. > Only because that person didn't think to check it in and tag it. They very well could have since they had direct commit access. -- 真実はいつも一つ!/ Always, there's only one truth! -- _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue