FS#69968 - [qtile] use signed git tag

Attached to Project: Community Packages
Opened by T.J. Townsend (blakkheim) - Saturday, 13 March 2021, 00:18 GMT
Last edited by David Runge (dvzrv) - Friday, 26 March 2021, 18:13 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To David Runge (dvzrv)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
Attached diff switches the qtile package to use a PGP-signed git tag for authenticity.

Additional info:
Key is on keyserver.ubuntu.com
This task depends upon

Closed by  David Runge (dvzrv)
Friday, 26 March 2021, 18:13 GMT
Reason for closing:  Won't implement
Additional comments about closing:  Upstream does not provide chain of trust and a document stating valid PGP key IDs used for releases.

https://github.com/qtile/qtile/issues/23 27 tracks this upstream
Comment by David Runge (dvzrv) - Friday, 26 March 2021, 17:54 GMT
@mysta: Thanks for the report.

As long as upstream does not provide a central document about who is the release manager, which keys are expected to be used for release verification and introduces a chain of trust, this change does not provide any improvement in regards to supply chain security.

Loading...