Re: New resource posted
Andras Mantia <[email protected]>
| Newsgroups | gmane.comp.kde.devel.quanta.user |
|---|---|
| Message-ID | <[email protected]> |
On Thursday 29 March 2007, Paul Lemmons wrote: > Ok, cool... I am getting closer... Now I get "Problematic Resource > FIle - No keys were found" with a request, should I continue or not. > Is this expected? It is up to you. The idea is that the resources can be signed with a PGP key, so you can be sure who uploaded it. This is important for scripts and toolbars, where you can actually execute code. Some resources were not signed (the person who created either doesn't have a PGP key or didn't want to sign it). Quanta will warn you if it was not signed at all or the signature is not a trusted one (by you), and you can choose how to go on. Accepting everything without thinking is similar to downloading something from the web and running on your computer without verifying. Luckily its all open source so you have a chance to verify the exact content of the package by getting it from the resource page (http://quanta.kdewebdev.org/resources.php). Or you can trust us that we didn't put mailicious code to the server, but as much as we try to verify the codes, we cannot legally guarantee 100% security for code not created by us (and even what we created comes without warranty according to the GPL licence). Andras -- Quanta Plus developer - http://quanta.kdewebdev.org K Desktop Environment - http://www.kde.org _______________________________________________ Quanta mailing list [email protected] https://mail.kde.org/mailman/listinfo/quanta
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iD8DBQBGC//vTQdfac6L/08RAr4BAJ9ilwAxz1aNcm8q6kd0A+EyTZB/KwCgr8lT NKU6jF5n/hP1lmbHb3FwGpk= =N/Pf -----END PGP SIGNATURE-----