Hello, On Wed 25 Aug 2021 at 12:00PM +02, Simon Richter wrote:
> Hi, > > On 8/25/21 1:21 AM, Sean Whitton wrote: > >> From my point of view, signing git tags is no less well established a >> best practice than signing tarballs -- in fact, to me, it seems *more* >> well established. > > That is ecosystem dependent. Yes, that was my point. We're going to have upstreams who release tarballs and upstreams who release tags for some time. -- Sean Whitton
signature.asc
Description: PGP signature