Re: Is md5sum compulsion in review instead sha1sum?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




Le Mer 14 octobre 2009 05:47, Chris Weyl a écrit :
>
> On Mon, Oct 12, 2009 at 10:13 PM, Matthias Clasen <mclasen@xxxxxxxxxx> wrote:

>> That part of the review guidelines has always struck me as bizarre.
>> After all, wouldn't it seem even better to compare the actual tarballs
>> with each other, byte-by-byte, than relying on a checksum ?
>
> Um.  An easily reproducible, cryptographically strong checksum? :)

This is one test I never do, nothing will stop the packager from changing the
packaged archive as soon as the review is finished, so the whole thing is a
major waste of time for everyone involved IMHO (as is posting specs in
addition to SRPMs BTW.

-- 
Nicolas Mailhot


--
Fedora-packaging mailing list
Fedora-packaging@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-packaging

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite Forum]     [KDE Users]

  Powered by Linux