From: Michael Witten Date: Wed, 28 Sep 2011 00:07:58 GMT Subject: Re: Lack of detached signatures Message-ID: In-Reply-To: <7vty7xttxh.fsf@alter.siamese.dyndns.org> On Wed, Sep 28, 2011 at 00:03, Junio C Hamano wrote: > Joseph Parmelee writes: > >> Under the present circumstances, and particularly considering the >> sensitivity of the git code itself, I would suggest that you implement >> signed detached digital signatures on all release tarballs. > > Well, signed tags are essentially detached signatures. People can verify > tarballs against them if they wanted to, although it is a bit cumbersome. Aren't tarballs used to get git on machines that don't yet have git?