sorry John, I forgot about your MR and commited the update in the meantime. Thank you very much for your contribution.
-
116b30e5 · upgpkg: 6.18-1
- ... and 1 more commit. Compare 24fc6935...116b30e5
Thank you for the link, however that is not a cryptographic chain of trust. In a short, when we opt-in for signed upstream sources we need to make ...
Here's some resources on that:...
we still need to figure out a cryptographic chain of trust here
Doing that with MD5 is not a bad idea, since they also provide those
That sounds reasonable, can you please put a comment with the link above the hashsums? You can also use dual-hashing by providing both, the old as ...
I changed the algorithm because the package provider provides sha256sums on their Github and Gitlab but not sha512sums...
please do not change the hash algorithm
Hi @antiapple4life , can you show the chain of trust between the new and old key?