limpkin / mooltipass

Github repository dedicated to the mooltipass project
https://www.themooltipass.com
521 stars 113 forks source link

GPG signatures for source validation #289

Open NicoHood opened 7 years ago

NicoHood commented 7 years ago

As we all know, today more than ever before, it is crucial to be able to trust our computing environments. One of the main difficulties that package maintainers of Linux distributions face, is the difficulty to verify the authenticity and the integrity of the source code.

The Mooltipass users would appreciate it if you would provide us GPG signatures in order to verify easily and quickly of your source code releases.

Overview of the required tasks:

Additional Information:

Thanks.

limpkin commented 7 years ago

We might do that when the official firmware for the mini is released.

NicoHood commented 7 years ago

Your commits are still not signed yet. Please do so, the earlier you start, the better it is. It is super easy to sign git commits: https://github.com/NicoHood/NicoHood.github.io/wiki/How-to-sign-sources-with-GPG-in-under-5-minutes