Thursday, July 04, 2024

Re: how to verify OpenBSD CVS repositories from mirrors?

Дана 24/07/05 05:29AM, Stuart Longland VK4MSL написа:
> Are the commits digitally signed? No, this is CVS not git.

When/if got(1) replace CVS, then `got tag -s` will allow tags to be
signed using SSH keys.


@topic:
> how to verify OpenBSD CVS repositories from mirrors?

Read every line of code of every file very carefully. If you spot any
malicious code, please report it along with the mirror in question.
Thanks in advance!

No comments:

Post a Comment