Community Packages

Please read this before reporting a bug:
http://wiki.archlinux.org/index.php/Reporting_Bug_Guidelines

Do NOT report bugs when a package is just outdated, or it is in Unsupported. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#68271 - [containerd] use signed git tag

Attached to Project: Community Packages
Opened by mysta (mysta) - Thursday, 15 October 2020, 18:11 GMT
Last edited by Morten Linderud (Foxboron) - Tuesday, 01 December 2020, 21:55 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Morten Linderud (Foxboron)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
Attached diff switches the containerd package to use a PGP-signed git tag for the source.

Additional info:
The unused $_commit variable was also removed in this change.
This task depends upon

Closed by  Morten Linderud (Foxboron)
Tuesday, 01 December 2020, 21:55 GMT
Reason for closing:  Fixed
Additional comments about closing:  1.4.2-1
Comment by Morten Linderud (Foxboron) - Thursday, 15 October 2020, 18:38 GMT
They have had no policy on tag signing/commit signing and all the objects thus far has been a hit and miss if it's signed by a dev, another dev or github actions. Have you talked with upstream about this or blindly suggesting a change?
Comment by mysta (mysta) - Thursday, 15 October 2020, 20:06 GMT
Hi Morten,

The last 10 tags on Github have all been signed by Derek McGowan's 0xF58C5D0A4405ACDB key as far as I can see. Can you clarify what you mean by there being no policy or it's "a hit or miss"? I can contact upstream if you tell me what the problem is.

Loading...