Checksums in release announcements and website
Jörg Sommer <[email protected]>
| Newsgroups | gmane.comp.shells.zsh.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, it would be helpful to harden the chain of trust, if the release announcement mails and the website https://zsh.sourceforge.io/releases.html would contain checksums of the tar.xz. And because the PGP key exists, would it be possible to sign the announcement mail? BTW: Having the key next to the tar is helpful, but if an attacker can change the tar, it can also change the zsh-keyring. Having this file also at https://zsh.sourceforge.io/ would be good. Best regards, Jörg -- Ich halte ihn zwar für einen Schurken und das was er sagt für falsch – aber ich bin bereit mein Leben dafür einzusetzen, daß er seine Meinung sagen kann. (Voltaire)
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABEIAB0WIQS1pYxd0T/67YejVyF9LJoj0a6jdQUCah/SuAAKCRB9LJoj0a6j dVnPAQCTnbNx4AL3I54W4fZUgmUGoXuZcRraf9EaGkZkJLCd0AD+LUyEOmLM4gb7 3biEOw7CXrP7u20razwqELHd7mi/iBg= =qxHh -----END PGP SIGNATURE-----