[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: PROPOSAL: GPG Signing of Releases

From: Justin Erenkrantz <justin_at_erenkrantz.com>
Date: 2004-04-13 06:17:47 CEST

--On Monday, April 12, 2004 10:27 AM -0500 kfogel@collab.net wrote:

> Oh -- if we're going to bound forever to use it, then I wouldn't
> create it. The potential to abandon it is a precondition of the
> experiment, as far as I'm concerned.
>
> Do you think its absence later would cause real worry?

Yes. If I were to see a key entitled 'Subversion Release Key' on, say, 1.0.2
then for 1.1, I don't see it, I could envision that users would be
legitimately concerned that the key wasn't used to sign 1.1. So, if we
introduce it, I think we must intend to use it for all subsequent releases.
-- justin

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Tue Apr 13 05:17:50 2004

This is an archived mail posted to the Subversion Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.