New t50 release (5.6.8)
Gianfranco Costamagna
locutusofborg at debian.org
Fri Oct 14 17:32:49 UTC 2016
Hi
sponsored! thanks you all for the nice work/verify/discussion!
I hope we will get signed tarballs soon, but for now I don't think
we have an easy way to verify signed commits
(unless you download both repositories and run git verify or whatever)
or import the new tarballs with something like what I do on borgbackup
gbp import-orig ../borgbackup-1.0.7.tar.gz --upstream-vcs-tag "1.0.7" --pristine-tar
this way you will have both tarball and upstream history in debian packaging,
and you will be able to verify it.
HTH
cheers!
G.
More information about the Pkg-security-team
mailing list