all messages for Emacs-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
* is melpa just unsigned?
@ 2023-05-18  4:21 Samuel Wales
  2023-05-19  0:02 ` Michael Heerdegen
  0 siblings, 1 reply; 10+ messages in thread
From: Samuel Wales @ 2023-05-18  4:21 UTC (permalink / raw)
  To: help-gnu-emacs

i can't seem to find out whether melpa is just plain unsigned as part
of its design, or if the archive-contents file is just plain unsigned
and packages might or might not be, or if the archive-contents file is
supposed to be signed but is not.

as a debian user, i am used to all packages AND the package list being
signed [i think].  i do not know all the security implications of not
signing an archive list, but it sounds dodgy.  in any case, the error
should definitely not be there?

if the archive contents file is not signed, what does htis mean in
practice?  what are the attack vectors?

am i going to have to inspect every line of code in all packages?
this isn't practical.

it seems gnu elpa is all signed and sealed and delivered.  so i feel
comfortable inasmuch as that helps.  why not melpa?

but gnu elpa does not have the packages that i need.  i am new to
packages.  i just upgraded to 27.1 and getting lots of bugs and
glitches.  i hope i can get some wisdom from this list on the above
questions.

in particular, why am i getting that error and does melpa sign its
package archive?  thanks.  please cc: me.

On 5/17/23, Samuel Wales <samologist@gmail.com> wrote:
> i tried everything suggested i coud find on the web and i still get:
>
>   Unsigned file ‘archive-contents’ at https://melpa.org/packages/ [2 times]
>
> whenever i try to list-packages.  package-refresh-contents resilts in
>
>   Failed to download ‘melpa’ archive.
>
> i have tried renaming ~/.emacs.d/elpa, the melpa subdir, the gnupg
> subdir.  the gnupg subdir ends up with different contents each time i
> try it, it seems.  any help apprecited.
>
> On 5/16/23, Samuel Wales <samologist@gmail.com> wrote:
>> i am the king of writing help messages to this list that do not get
>> replied to.  i am trying to make them comprehensible and answerable
>> but there are often significant limitations.
>>
>> On 5/15/23, Samuel Wales <samologist@gmail.com> wrote:
>>>   ;; [2023-05-15 Mon]
>>>   ;; i am new to emacs packages, but not new to emacs
>>>   ;; i recently upgraded to emacs 27
>>>   ;; i followed these instructions from melpa:
>>>   (require 'package)
>>>   (add-to-list 'package-archives '("melpa" .
>>> "https://melpa.org/packages/")
>>> t)
>>>   (setq package-check-signature 'all)
>>>   (package-initialize)
>>>   ;; i installed gnu-elpa-keyring-update from elpa
>>>   ;; problems:
>>>   ;; 1.  startup takes 9s instead of 4s
>>>   ;; 2.  when i do m-x list-packages, i get error in echo area.
>>> messages buffer says:
>>>   ;; Importing package-keyring.gpg...done
>>>   ;; Package refresh done
>>>   ;; error in process sentinel: Unsigned file ‘archive-contents’ at
>>> https://melpa.org/packages/ [2 times]
>>>   ;; package list shows up, but it does not seem wise to install
>>> anything.
>>>
>>>
>>> --
>>> The Kafka Pandemic
>>>
>>> A blog about science, health, human rights, and misopathy:
>>> https://thekafkapandemic.blogspot.com
>>>
>>
>>
>> --
>> The Kafka Pandemic
>>
>> A blog about science, health, human rights, and misopathy:
>> https://thekafkapandemic.blogspot.com
>>
>
>
> --
> The Kafka Pandemic
>
> A blog about science, health, human rights, and misopathy:
> https://thekafkapandemic.blogspot.com
>


-- 
The Kafka Pandemic

A blog about science, health, human rights, and misopathy:
https://thekafkapandemic.blogspot.com



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2023-05-29 13:12 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-05-18  4:21 is melpa just unsigned? Samuel Wales
2023-05-19  0:02 ` Michael Heerdegen
2023-05-20 19:00   ` Emanuel Berg
2023-05-21 23:36     ` Michael Heerdegen
2023-05-23  2:53       ` Samuel Wales
2023-05-23  3:17         ` Platon Pronko
2023-05-23  3:21         ` [External] : " Drew Adams
2023-05-23 17:47         ` Daniel Fleischer
2023-05-26  6:07           ` Samuel Wales
2023-05-29 13:12           ` Björn Bidar

Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/emacs.git
	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.