Open andrewdavidwong opened 7 years ago
+1
One issue that @rootkovska raised awhile back was that the easiest install process for OpenTimestamps is to install dependencies via Python's insecure pip packaging system; we should discuss further what needs to be done to securely package OpenTimestamps for use in the QubesOS development environment.
Also, re: actually timestamping Git repos, this is the relevant blog post describing how that works: https://petertodd.org/2016/opentimestamps-git-integration
Another discussion thread: https://groups.google.com/d/topic/qubes-devel/ilxC6UpkZz4/discussion
There is a hope: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921251
At a minimum, in qubes-secpack, and eventually in most repos.
Discussion: https://groups.google.com/d/topic/qubes-devel/b0s6ZA8fmQQ/discussion
CC @petertodd