-
Notifications
You must be signed in to change notification settings - Fork 229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
distribution packages should be GPG signed #188
Comments
Good timing, I would really like to see this. FYI, even though you decided "not to do checksums" and just do gpg, the way the process usually works is that the checksum is stored in a file, and then a signature is provided for that file. See the Ubuntu releases for an example. (Don't copy their lack of https, however :) Generating the checksums is easy ( Thanks, |
@evancox10 The jars are already signed when they're published to Maven Central (see 2.12.6 for example), so I assume there's already a key that can easily be used for this |
@hamzaremmal since you're looking at related work for Scala 3, just FYI that this ticket exists and never attracted much attention 🤷 |
note that https://scala-lang.org/security/ exists now (since scala/scala-lang#1661), so we now have a central place where we can put information about this sort of thing |
as suggested by @jarrodu at scala/scala-lang#463
The text was updated successfully, but these errors were encountered: