[python-ldap] signed releases

Petr Viktorin pviktori at redhat.com
Mon Jan 28 11:02:54 EST 2019


On 1/25/19 3:04 PM, Philipp Gesang wrote:
> Hey guys,

Hello!
(I assume not only guys are included?)

> the official(?) repo doesn’t appear to have signed tags and the
> tarballs [1] are not accompanied by signature files either.

I don't normally use a signature, and I'm not part of any webs of trust, 
so I'm not sure what a signed release would accomplish.
Could you explain the security model a signature would allow, and what 
kind of security practices you'd expect the signer to follow?

> Consequently it’s not easy to establish the provenance of
> releases.

Those tarballs are generated by GitHub from the corresponding Git commit.

> Would it be possible to provide signed release tarballs or at
> least sign release tags?
>
> Please Cc: me, as I’m not subscribed.

Please don't forget to reply to the list :)


> [0] https://github.com/python-ldap/python-ldap/
> [1] E. g. https://github.com/python-ldap/python-ldap/releases/tag/python-ldap-3.1.0


More information about the python-ldap mailing list