[ 
https://issues.apache.org/jira/browse/CASSANDRA-14968?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16738235#comment-16738235
 ] 

Stefan Podkowinski commented on CASSANDRA-14968:
------------------------------------------------

How would you verify the integrity of builds that come with such bintray 
signatures, without reproducable builds? How would we make sure that only 
official releases will be signed with the uploaded key?

> Investigate GPG signing of deb and rpm repositories via bintray
> ---------------------------------------------------------------
>
>                 Key: CASSANDRA-14968
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-14968
>             Project: Cassandra
>          Issue Type: Bug
>            Reporter: Michael Shuler
>            Priority: Major
>              Labels: packaging
>
> Currently, the release manager uploads debian packages and built/signed 
> metadata to a generic bintray repository. Perhaps we could utilize the GPG 
> signing feature of the repository, post-upload, via the bintray GPG signing 
> feature.
> https://www.jfrog.com/confluence/display/BT/Managing+Uploaded+Content#ManagingUploadedContent-GPGSigning
>  Depends on CASSANDRA-14967



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to