Debian sources have limited file integrity
Luke <[email protected]>
| Newsgroups | gmane.linux.debian.devel.www |
|---|---|
| Message-ID | <[email protected]> |
Hello, Many downstream projects are using your source files directly from your FTP and packaging. This presents a problem. 1) Navigate to https://ftp.de.debian.org/debian/pool/main/ 2) Click on ANY folder/subfolder of a popular project. 3) The only checksum can be found in the .dsc file. While having the .dsc file is better than nothing, it does not allow downstream to run GPG verification against the source files themselves. Additionally, .dsc files only have SHA256 as the strongest checksum. SHA1 and MD5 have been considered weak/broken for some time, per Debian's own documentation. Please consider implementing a system similar to kernel.org's - https://mirrors.kernel.org/sourceware/lvm2/releases/ In this scenario, each source tarball is signed with GPG, and a SHA512SUM is included for the entire directory as well. Downstream can then verify the GPG signature and the checksum easily. Thank you for your time and concern. Sincerely, Luke Parabola GNU/Linux-libre Packager
signature.asc
(application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJYJ9J6AAoJEMP0/88+roaXeakP/iQe/BBMvj1D/iq+iRRAI1wB povmCZnUPq8xw/q0N8Fs23le5rxerx4YRbOmWSKNrmlhjgEGY8yehxRAccPmk5Ij I2AxcLkEH3iNd18H1p+gAiVI7mG6mIBByIctny0DLvVbInHicw8Q6M/7eOvRXF+x D3AOAmQw3NhU7gs0ikYQeGeVSbn4qiuTSIzc2n3RpWTNrbbyyLb8rPGayUpCrv7Y IVBkn5Yy27rYumE07H62zN2OtES7zayejevZ+KCblkJCoI+r2fRAoIOirjr/Pc9F PdALdMW/S7Fy3w9xPS3UrbUpIEW+42ysm095KuAtwMjLmfGT10LE3sueTs7TuHtw wWBxsCYymHRASx7i+mZiA2ikgUaeP2G9QOnoaIeBNaK/9Id5qOwSUTvJsBtB2wmu tQxBnZjsl9NarC/rzNJImKuoefDmlgA1tRl/UrBZYGAXhDlL/j5p3b765Y6FRcP+ BJC2uunSv0AD+UsHsjlMEz3dvPcicU7nZ0Klq9jasu+uBChYYXgNEdsWyMFDSjuB SWJDSOp9Z7ilwLxHM77T/L0famnAayMjb2nLuStgJb2GTASIdJLfHcIUudiW06nl Ewx4/cWv8VOWpk6l3anOuKH740wVi0mkJ2ehBkbKl/3DGLXbgWJknuwLmGnU06hR xwz6Q/k3UEcEsi21dDC2 =Z/4D -----END PGP SIGNATURE-----