[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Request for Sponsorship



On Sun, Jul 20, 2014 at 5:55 AM, Vincent Cheng wrote:

> Feel free to ignore that tag if upstream doesn't sign their release
> tarballs. It's by no means mandatory, just nice to have (hence
> "pedantic").

In a world where we have an active worldwide network adversary (and
probably more than one), I would say signing and verifying release
tarballs and VCS commits is more important than 'pedantic' :)

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


Reply to: