Re: Lack of detached signatures
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 28, 2011, 00:03 UTC
- Message-ID
- <7vty7xttxh.fsf@alter.siamese.dyndns.org>
- In-Reply-To
- <alpine.LNX.2.00.1109271742460.24832@bruno>
Joseph Parmelee <jparmele@wildbear.com> writes:
> Under the present circumstances, and particularly considering the > sensitivity of the git code itself, I would suggest that you implement > signed detached digital signatures on all release tarballs.
Well, signed tags are essentially detached signatures. People can verify tarballs against them if they wanted to, although it is a bit cumbersome.