[python-ldap] signed releases
Petr Viktorin
pviktori at redhat.com
Mon Jan 28 11:02:54 EST 2019
On 1/25/19 3:04 PM, Philipp Gesang wrote:
> Hey guys,
Hello!
(I assume not only guys are included?)
> the official(?) repo doesn’t appear to have signed tags and the
> tarballs [1] are not accompanied by signature files either.
I don't normally use a signature, and I'm not part of any webs of trust,
so I'm not sure what a signed release would accomplish.
Could you explain the security model a signature would allow, and what
kind of security practices you'd expect the signer to follow?
> Consequently it’s not easy to establish the provenance of
> releases.
Those tarballs are generated by GitHub from the corresponding Git commit.
> Would it be possible to provide signed release tarballs or at
> least sign release tags?
>
> Please Cc: me, as I’m not subscribed.
Please don't forget to reply to the list :)
> [0] https://github.com/python-ldap/python-ldap/
> [1] E. g. https://github.com/python-ldap/python-ldap/releases/tag/python-ldap-3.1.0
More information about the python-ldap
mailing list