BoostIO / BoostNote-Legacy

This repository is outdated and new Boost Note app is available! We've launched a new Boost Note app which supports real-time collaborative writing. https://github.com/BoostIO/BoostNote-App
Other
17.07k stars 1.47k forks source link

GPG signatures for source validation #387

Open NicoHood opened 7 years ago

NicoHood commented 7 years ago

As we all know, today more than ever before, it is crucial to be able to trust our computing environments. One of the main difficulties that package maintainers of Linux distributions face, is the difficulty to verify the authenticity and the integrity of the source code.

The Arch Linux team would appreciate it if you would provide us GPG signatures in order to verify easily and quickly your source code releases.

Overview of the required tasks:

GPGit is meant to bring GPG to the masses. It is not only a shell script that automates the process of creating new signed git releases with GPG but also comes with this step-by-step readme guide for learning how to use GPG.

Additional Information:

Thanks in advance.

digital-abyss commented 6 years ago

:+1:

GlassGruber commented 5 years ago

Hei there any update on this? Even a basic dump of checksums to verify the the packaged distributed bins would be a welcome improvement! Or have I missed them in some documentation page?

Flexo013 commented 5 years ago

@GlassGruber This is definitely something that we will be working towards.

Sorry about not replying/acknowledging this issue sooner.