emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Signing git tags for releases


From: Eli Zaretskii
Subject: Re: Signing git tags for releases
Date: Thu, 09 Dec 2021 09:37:20 +0200

> From: Stefan Kangas <stefan@marxist.se>
> Date: Wed, 8 Dec 2021 14:06:33 -0800
> Cc: emacs-devel@gnu.org
> 
> There have been no other comments within a week, besides the one from
> Teemu Likonen who spotted a mistake in the patch I proposed.
> 
> If anyone has anything more to add here, there is still some time to
> speak up before it is time for the second pretest.  If I don't see any
> further comments until then, I will go ahead with the proposed plan.

At least one important aspect remains un-discussed: how do we make
sure the keys of those who sign tags are made available for the
others, who'd like to verify the signatures.  This will have to be
described in CONTRIBUTE, with enough detail for people to follow even
if they aren't experts in GnuPG use.

More generally, what exactly is proposed?  I think it would be good to
see some text for CONTRIBUTE and/or make-tarball.txt (or other docs)
with what will be the procedures related to this.

IOW, I don't think the discussion, such as it was, was detailed
enough, and I won't be surprised if people didn't really understand
what we are going to change and how.  This gap needs to be filled
before we can conclude that "everyone is in favor".

Thanks.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]