timescale / timescaledb

An open-source time-series SQL database optimized for fast ingest and complex queries. Packaged as a PostgreSQL extension.
https://www.timescale.com/
Other
17.93k stars 882 forks source link

Package signature #713

Open rdunklau opened 6 years ago

rdunklau commented 6 years ago

Hello,

Could you provide a GPG signature for your packages, or another mean of verifying their integrity before installing them ?

Thank you !

RobAtticus commented 6 years ago

Which packages in particular are missing GPG? All our Debian-based ones should be signed, but I suppose RPM and other platforms are missing.

rdunklau commented 6 years ago

I'm working with debian packages. I did not know that debian packages could embed their signature themselves.

However, it looks like the package is not signed, since debsigs --list doesn't return anything:

debsigs --list timescaledb-postgresql-10_0.9.2~debian9_amd64.deb
GPG signatures in timescaledb-postgresql-10_0.9.2~debian9_amd64.deb:
 *** NO ATTEMPT HAS BEEN MADE TO VERIFY THE LISTED SIGNATURES ***
RobAtticus commented 6 years ago

Interesting, I guess it's just the source packages that end up signed, I will investigate a way to improve this. Thanks!

sander85 commented 1 year ago

5 years has passed and the RPMs are still not signed :unamused:

Thulium-Drake commented 10 months ago

@svenklemm @erimatnor @cevian Ping, can we please get an update on this? Multiple people have opened and/or mentioned this is a real problem for them (same goes for me).

https://www.timescale.com/forum/t/gpg-key-check-failed-for-unsigned-package/1250

Thulium-Drake commented 10 months ago

@NunoFilipeSantos Ping, can we get an update? :)

thanasisk commented 10 months ago

@Thulium-Drake hello there! This item is on my radar for the near future. I will keep you posted.

Thulium-Drake commented 4 months ago

@thanasisk any update? :-)

thanasisk commented 3 months ago

@thanasisk any update? :-)

Hello there, this is due in the immediate future (as in next few weeks)

thanasisk commented 3 months ago

@Thulium-Drake you prefer .deb or .rpm support to come first?

Thulium-Drake commented 3 months ago

@thanasisk We're currently running into this issue with RHEL, so I'd prefer RPM :-)

Thanks! :rocket: