Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add gpg signature files (.asc) to binary downloads #4578

Open
1 task done
RubenKelevra opened this issue Feb 9, 2023 · 1 comment
Open
1 task done

Add gpg signature files (.asc) to binary downloads #4578

RubenKelevra opened this issue Feb 9, 2023 · 1 comment

Comments

@RubenKelevra
Copy link

RubenKelevra commented Feb 9, 2023

Is there an existing issue for this?

  • I have searched the existing issues

Berty product

Desktop app

Feature request

Hey guys,

I'm the maintainer for the AUR packages for ArchLinux:

I was wondering if it's possible to add an signature to the downloads, so I can add the valid GPG key ID and the user downloading/installing the binaries can thus verify automatically that the files are valid.

Context

AUR packages are “just” the instructions which files the user needs to fetch and have either a checksum or a GPG key ID – instead of a prebundled binary package which just needs to be extracted, like a .deb, .rpm, .pkg.tar.

If a GPG key ID is supplied, the AUR-helper (basically just an extended package manager), will fetch the GPG key from the key servers and check the files with it.

Possible implementation

No response

@jefft0
Copy link
Collaborator

jefft0 commented Jul 7, 2023

We have various requests for alternative distribution channels. Put this in the backlog until we have to time to review.

@jefft0 jefft0 added the backlog label Jul 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants