Hi Simon, On Fri, Jan 19, 2024 at 05:32:05PM +0100, Simon Josefsson wrote: > * URL : https://git.glasklar.is/sigsum/core/sigsum-go > Description : tools for public and transparent logging of signed checksums > > The goal of Sigsum is to provide building blocks that can be used to > enforce public logging of signed checksums. do you think this would be a suitable tool to publically log all checksums of all Debian source and binary packages published? -- cheers, Holger ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ holger@(debian|reproducible-builds|layer-acht).org ⢿⡄⠘⠷⠚⠋⠀ OpenPGP: B8BF54137B09D35CF026FE9D 091AB856069AAA1C ⠈⠳⣄ Life may not be the party we hoped for, but while we're here we might as well dance!
Attachment:
signature.asc
Description: PGP signature