Checksums in release announcements and website

Jörg Sommer <[email protected]>
Newsgroups gmane.comp.shells.zsh.devel
Message-ID <[email protected]>
Hi,

it would be helpful to harden the chain of trust, if the release
announcement mails and the website https://zsh.sourceforge.io/releases.html
would contain checksums of the tar.xz.

And because the PGP key exists, would it be possible to sign the
announcement mail?

BTW: Having the key next to the tar is helpful, but if an attacker can
change the tar, it can also change the zsh-keyring. Having this file also at
https://zsh.sourceforge.io/ would be good.


Best regards, Jörg

-- 
Ich halte ihn zwar für einen Schurken und das was er sagt für
falsch – aber ich bin bereit mein Leben dafür einzusetzen, daß
er seine Meinung sagen kann.            (Voltaire)
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABEIAB0WIQS1pYxd0T/67YejVyF9LJoj0a6jdQUCah/SuAAKCRB9LJoj0a6j
dVnPAQCTnbNx4AL3I54W4fZUgmUGoXuZcRraf9EaGkZkJLCd0AD+LUyEOmLM4gb7
3biEOw7CXrP7u20razwqELHd7mi/iBg=
=qxHh
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.