Re: DRAFT: SourceURL addition/clarification - Git Hosting Services

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On Jun 26, 2015 9:30 PM, "Kevin Fenzi" <kevin@xxxxxxxxx> wrote:

> In the final case, if the checksum differed it meant that the
> maintainer made a mistake uploading or upstream changed the same
> release after it was released.

Or somewhere between upstream and us the tarball was modified (someone hacked github, someone gained commit to upstream and then tried top cover their tracks, a malicious package maintainer on our side, etc)  This is the case that we definitely want to raise warning flags about.

-Toshio

--
packaging mailing list
packaging@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/packaging

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite Forum]     [KDE Users]

  Powered by Linux