Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #111317

Re: New supply-chain security tool: backseat-signed

From Guillem Jover <guillem@debian.org>
Newsgroups linux.debian.devel
Subject Re: New supply-chain security tool: backseat-signed
Date 2024-04-06 14:30 +0200
Message-ID <Iqdlf-4rx3-13@gated-at.bofh.it> (permalink)
References <Iq8Yn-4oGU-313@gated-at.bofh.it> <Iq8Yn-4oGU-311@gated-at.bofh.it> <Iq8Yu-4oGU-697@gated-at.bofh.it> <Iq8Zy-4oGU-3017@gated-at.bofh.it> <Iqcfv-4qPN-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi!

On Sat, 2024-04-06 at 19:13:22 +0800, Sean Whitton wrote:
> On Fri 05 Apr 2024 at 01:31am +03, Adrian Bunk wrote:
> > Right now the preferred form of source in Debian is an upstream-signed
> > release tarball, NOT anything from git.
> 
> The preferred form of modification is not simply up for proclamation.
> Our practices, which are focused around git, make it the case that
> salsa & dgit in some combination are the preferred form for modification
> for most packages.

People keep bringing this up, and it keeps making no sense. I've
covered this over the years in:

  https://lists.debian.org/debian-devel/2014/03/msg00330.html
  https://lists.debian.org/debian-project/2019/07/msg00180.html

(There's in addition the part that Adrian covers in another reply.)

Thanks,
Guillem

Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Re: New supply-chain security tool: backseat-signed Adrian Bunk <bunk@debian.org> - 2024-04-06 09:50 +0200
  Re: New supply-chain security tool: backseat-signed Jeremy Stanley <fungi@yuggoth.org> - 2024-04-06 09:50 +0200
  Re: New supply-chain security tool: backseat-signed kpcyrd <kpcyrd@archlinux.org> - 2024-04-06 09:51 +0200
    Re: New supply-chain security tool: backseat-signed Adrian Bunk <bunk@debian.org> - 2024-04-06 09:51 +0200
      Re: New supply-chain security tool: backseat-signed kpcyrd <kpcyrd@archlinux.org> - 2024-04-06 09:51 +0200
        Re: New supply-chain security tool: backseat-signed Adrian Bunk <bunk@debian.org> - 2024-04-06 09:52 +0200
      Re: New supply-chain security tool: backseat-signed James McCoy <jamessan@debian.org> - 2024-04-06 09:52 +0200
      Re: New supply-chain security tool: backseat-signed Sean Whitton <spwhitton@spwhitton.name> - 2024-04-06 13:20 +0200
        Re: New supply-chain security tool: backseat-signed Adrian Bunk <bunk@debian.org> - 2024-04-06 14:10 +0200
          Re: New supply-chain security tool: backseat-signed kpcyrd <kpcyrd@archlinux.org> - 2024-04-06 16:20 +0200
            Re: New supply-chain security tool: backseat-signed Adrian Bunk <bunk@debian.org> - 2024-04-06 17:00 +0200
            Re: New supply-chain security tool: backseat-signed Simon McVittie <smcv@debian.org> - 2024-04-06 17:40 +0200
              Re: New supply-chain security tool: backseat-signed Jeremy Stanley <fungi@yuggoth.org> - 2024-04-06 18:00 +0200
              Re: New supply-chain security tool: backseat-signed "Theodore Ts'o" <tytso@mit.edu> - 2024-04-11 17:00 +0200
              Re: New supply-chain security tool: backseat-signed "G. Branden Robinson" <g.branden.robinson@gmail.com> - 2024-04-11 20:30 +0200
                Re: New supply-chain security tool: backseat-signed Colin Watson <cjwatson@debian.org> - 2024-04-12 01:20 +0200
              Re: New supply-chain security tool: backseat-signed "Theodore Ts'o" <tytso@mit.edu> - 2024-04-11 16:30 +0200
                Re: New supply-chain security tool: backseat-signed Colin Watson <cjwatson@debian.org> - 2024-04-11 16:40 +0200
          Re: New supply-chain security tool: backseat-signed Sean Whitton <spwhitton@spwhitton.name> - 2024-04-07 09:50 +0200
        Re: New supply-chain security tool: backseat-signed Guillem Jover <guillem@debian.org> - 2024-04-06 14:30 +0200
          Re: New supply-chain security tool: backseat-signed Sean Whitton <spwhitton@spwhitton.name> - 2024-04-07 09:50 +0200

csiph-web