- Notifications
You must be signed in to change notification settings - Fork 57
BTS-793 | Add how SHA256 hash of download can be checked #926
Conversation
debian / RPM => repositories and their meta data are signed, packages themselves only indirectly. Package signing has been discarded by the debian team. |
FYI: Our .rpm files can apparently be validated using
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@Simran-B can you please apply these changes to 3.9 (the current stable version) as well? Otherwise, lgtm.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
See comments.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM.
Initial work on adding verification instructions:
Anything else? .asc, GPG?