Re: Alternative signature mechanisms for upstream source verification
Mathias Behrle <[email protected]>
| Newsgroups | gmane.linux.debian.devel.dpkg.general,gmane.linux.debian.devel.general,gmane.linux.debian.devel.python |
|---|---|
| Organization | . |
| Message-ID | <[email protected]> |
* Stefano Rivera: " Alternative signature mechanisms for upstream source verification" (Fri, 4 Oct 2024 18:21:01 +0000): [...] > Should we expand this to include some of these new mechanisms? > Things brought up in the debian-python thread include: > 1. sigstore https://docs.sigstore.dev/ > 2. ssh signatures > 3. signify https://man.openbsd.org/signify.1 JFTR: Tryton moved from pgp signatures to signify, so of course I would appreciate if this format could be handled as well.