Replies: 5 comments 1 reply
-
Hi @inglor, Are you planning to package it for community repo? There are already packages in AUR. |
Beta Was this translation helpful? Give feedback.
-
Yes - sorry it might not be clear since I use I'm As for the commit tag signed see an example from That way Arch Linux tools can verify the commit of the tag directly during build. Some more info from https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work |
Beta Was this translation helpful? Give feedback.
-
@inglor Ok, I will try to sign all commits from now. Great! Looking forward to seeing gdu in community. |
Beta Was this translation helpful? Give feedback.
-
@dundee new release with signed commits looks awesome! Package updated and it's ready for repos, just waiting for the keyring to be updated with my key, takes a bit of time. Thanks for sorting this out this quickly! |
Beta Was this translation helpful? Give feedback.
-
Hi @dundee
Since you already have PGP uploaded to github 1 please consider signing your tags (releases) at least, if not all your commits. The benefits for this are detailed here 2
My plan is to package this on Arch Linux repos and it would assist on making sure the tagged source is valid.
Beta Was this translation helpful? Give feedback.
All reactions