From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from localhost (localhost [127.0.0.1]) by arlo.cworth.org (Postfix) with ESMTP id BB6B66DE0273 for ; Thu, 8 Feb 2018 22:28:07 -0800 (PST) X-Virus-Scanned: Debian amavisd-new at cworth.org X-Spam-Flag: NO X-Spam-Score: 0.085 X-Spam-Level: X-Spam-Status: No, score=0.085 tagged_above=-999 required=5 tests=[AWL=0.205, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=disabled Received: from arlo.cworth.org ([127.0.0.1]) by localhost (arlo.cworth.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FYTO2Eetc61a for ; Thu, 8 Feb 2018 22:28:06 -0800 (PST) Received: from mail-yw0-f180.google.com (mail-yw0-f180.google.com [209.85.161.180]) by arlo.cworth.org (Postfix) with ESMTPS id 736676DE026E for ; Thu, 8 Feb 2018 22:28:06 -0800 (PST) Received: by mail-yw0-f180.google.com with SMTP id c78so4402421ywb.13 for ; Thu, 08 Feb 2018 22:28:06 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=RkPwc2sPGmKIkHmhyT1SfjK16swIEG+AlfK1C51BSm4=; b=c96NkjrxgpiUuUq4yPQoNMuaCrZADOZsH9QL0mSRms0svZfF6lRXKak0VZXB3EwmoD y9ZzZC5QDVQJ7Z7zdUDG+sSG9vemVywJsjgxmMBND6zgio7eeZuf8TRBxZ1MhVLoLr6a Px5HPdLVqDlT7ZF8H16zJVhWgLBwI3XPwvbg5OSezgTORt1gLCYGT887jyoL1jw243nS YC6UrC2rZVAKKHdnEHGsn5pgDFnd54JZ4WUfTEr3CkKdHzvwjw9CxzY3GYzRWMfuL4su o6h4zGq+HbsBRV/RpNFENQgUxm5DpNxjJWV0FwZWLVHEqfYnxpD63dXVFs41wP6vT/8J az4g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=RkPwc2sPGmKIkHmhyT1SfjK16swIEG+AlfK1C51BSm4=; b=dDqAIObaC1jFiLcDcXJC12s3h3ETnTuOPH6F4qEovn80HSqUmR2vYJR6K3ccn0jlzy dBpKHXHP6qxuf4uz9S3QHlYi5Gaok/HjdWROtDkxOeKAEArRofPAA4href0RPsJCiPwL Ewq7b0/blvDrpAB7AdM1/Zmz3C0YzNCbSEZr4/u4aZBv+OzKws6okiFZBy7zEyqwmUMW Phipsw2X35KyT1lbjnvySkCOS1pNIqs4FJW/RBoMntl7x2IMcVM6169SGYh7eIbib3EV mwCmisVgSC9csYSSt25+4TtXTo0mcUkwBqDM5Isfik8WJ1+oztYm9wce2OBN5pE+fc4o CRpw== X-Gm-Message-State: APf1xPADQJCKkiaDqgj9Gn9OpxVCjydoPnRFPLUlkhgvOufCwQ2Q5pjI HdKFe/p+7aF1rSnhE+qLqA5JsMhB8yKyBM7Ugtk= X-Google-Smtp-Source: AH8x2270HR9p45QIcWz1VpXXwqbE1rOmbp3qQMAJWBZ8huLpcU4YnrJf4iT6pQPr/rq8iQUdcQDNjYSlXIrpyU4lJJQ= X-Received: by 10.129.70.193 with SMTP id t184mr1131364ywa.246.1518157685097; Thu, 08 Feb 2018 22:28:05 -0800 (PST) MIME-Version: 1.0 Sender: plaiceadam@gmail.com Received: by 10.37.130.145 with HTTP; Thu, 8 Feb 2018 22:28:04 -0800 (PST) In-Reply-To: <877ert30w3.fsf@fifthhorseman.net> References: <877ert30w3.fsf@fifthhorseman.net> From: Adam Plaice Date: Fri, 9 Feb 2018 06:28:04 +0000 X-Google-Sender-Auth: xeW6m1nBxV3CSDiPSNwBGc4KYOQ Message-ID: Subject: Re: Fetching from the git repositories over https? To: Daniel Kahn Gillmor Cc: notmuch@notmuchmail.org Content-Type: text/plain; charset="UTF-8" X-BeenThere: notmuch@notmuchmail.org X-Mailman-Version: 2.1.26 Precedence: list List-Id: "Use and development of the notmuch mail system." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 09 Feb 2018 06:28:07 -0000 Hi Daniel, Thanks very much for the reply. I fully agree that the verifying of git tags by MELPA would be valuable (and rather important from a security perspective), and will bring it up. BTW, is the GitHub mirror https://github.com/notmuch/notmuch/ mentioned in README.rst, semi-official in the sense of being likely to be up to date? If, yes, it could be used as a stopgap intermediary "source" for MELPA, until https transport is possible with the main notmuch repository or MELPA supports verifying signed git tags. Thanks again, Adam