From: Junio C Hamano Date: Wed, 28 Sep 2011 00:03:06 GMT Subject: Re: Lack of detached signatures Message-ID: <7vty7xttxh.fsf@alter.siamese.dyndns.org> In-Reply-To: Joseph Parmelee writes: > Under the present circumstances, and particularly considering the > sensitivity of the git code itself, I would suggest that you implement > signed detached digital signatures on all release tarballs. Well, signed tags are essentially detached signatures. People can verify tarballs against them if they wanted to, although it is a bit cumbersome.