Ticket UUID: | 1853e51989afa6fbfebd70c8e46c72640643e388 | ||
Title: | GPG sign the downloadable releases | ||
Status: | Fixed | Type: | Feature_Request |
Severity: | Critical | Priority: | |
Subsystem: | Resolution: | Fixed | |
Last Modified: | 2011-04-18 12:49:18 | ||
Version Found In: | |||
Description & Comments: | |||
Hi!
Please provide GPG-signed downloads on the download page. How can I trust the executables otherwise? It seems that fossil allows signing of each manifest / checkin, but the executable on the downloads page are unverified. Also it would be nice if the downloadable tar.gz or zip balls are signed. Thanks BB. anonymous claiming to be bert added on 2011-04-18 12:17:05 UTC: -- this post never had any reply it seems, although DRH cares much about security and likes GPG, as far as I can see, see for example: http://www.mail-archive.com/fossil-users@lists.fossil-scm.org/msg01611.html So I really think this request is reasonable. drh added on 2011-04-18 12:49:18 UTC: |