Uploaded image for project: 'Picard'
  1. Picard
  2. PICARD-2691

Provide code signed source archives

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Normal Normal
    • 2.9.1
    • None
    • Packaging & Deployment
    • None

      Since PyPI stopped supporting file signatures this broke download and verification for some upstream packagers, like Arch Linux.

      We should provide officially signed source packages. Currently the Github provided source downloads are used. Instead the CI build should generate custom source packages that we can code sign with the GnuPG key.

      The current code signing key is 68990DD0B1EDC129B856958167997E14D563DA7C

            outsidecontext Philipp Wolfer
            outsidecontext Philipp Wolfer
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:

                Version Package
                2.9.1