Supply chain security: PGP signature of archives? #465
Closed
tchoutri
started this conversation in
Feature Requests
Replies: 1 comment
-
This is not going to work because we optimise the tarballs we serve. We do store the originals but only to recover from data loss or when we tweak the optimisations of the tarballs we serve. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
When uploading archives to Flora, it would be interesting to include a detached PGP signature that would be verified by the server.
The main model I'm thinking of right now is GitHub, where you upload your PGP public key, sign commits with your private key, and the server can verify if the two match, and display a little green check.
Beta Was this translation helpful? Give feedback.
All reactions