unofficial mirror of bug-gnu-emacs@gnu.org 
 help / color / mirror / code / Atom feed
From: Rob Browning <rlb@defaultvalue.org>
To: Stefan Kangas <stefan@marxist.se>
Cc: John Wiegley <jwiegley@gmail.com>,
	Nicolas Petton <nicolas@petton.fr>,
	24461@debbugs.gnu.org
Subject: bug#24461: Signing Emacs git release tags
Date: Sun, 29 Sep 2019 12:24:16 -0500	[thread overview]
Message-ID: <87h84vkocf.fsf@trouble.defaultvalue.org> (raw)
In-Reply-To: <CADwFkmmP=TwtQKgkJ5uaVoqaZ3rgSxkTSKwmh6jxcxq=P_tc1A@mail.gmail.com>

Stefan Kangas <stefan@marxist.se> writes:

> I think signing tags is different than signing commits.  A signed tag
> means you can have more trust that you are using the code with the
> latest fix to security problem X, announced to have been released in
> tagged Emacs version Y, and not code missing that fix.

Fair enough -- I suppose without the signed tag, there's no way to be
completely sure that you have the right signed commit.

-- 
Rob Browning
rlb @defaultvalue.org and @debian.org
GPG as of 2011-07-10 E6A9 DA3C C9FD 1FF8 C676 D2C4 C0F0 39E9 ED1B 597A
GPG as of 2002-11-03 14DD 432F AE39 534D B592 F9A0 25C8 D377 8C7E 73A4





  reply	other threads:[~2019-09-29 17:24 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-09-18 18:12 bug#24461: Signing Emacs git release tags Rob Browning
2016-09-18 19:49 ` John Wiegley
2016-09-18 21:09   ` Nicolas Petton
2019-09-29  4:26 ` Stefan Kangas
2019-09-29 16:05   ` Rob Browning
2019-09-29 16:22     ` Stefan Kangas
2019-09-29 17:24       ` Rob Browning [this message]
2022-01-24 10:38 ` Lars Ingebrigtsen
2022-02-21 14:26   ` Lars Ingebrigtsen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

  List information: https://www.gnu.org/software/emacs/

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87h84vkocf.fsf@trouble.defaultvalue.org \
    --to=rlb@defaultvalue.org \
    --cc=24461@debbugs.gnu.org \
    --cc=jwiegley@gmail.com \
    --cc=nicolas@petton.fr \
    --cc=stefan@marxist.se \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).