W dniu pią, 06.07.2018 o godzinie 10∶11 +0200, użytkownik Manuel Rüger
napisał:
> I disagree with adding this as a requirement.
> 
> Services should explicitly fail to work with expired GPG keys, key
> renewal times should be at the key owner's descretion.
> This should still be a recommendation that guarantees the key owner to
> continue work without interruption.
> 

They do.  That is why we need the updates to happen early enough so that
the services can sync.  It's not nice when Gentoo repository
distribution is stalled because a developer changed his key and not all
services have synced yet.

I've only recently hit the case when my important fix wasn't distributed
to users immediately (= more users hit severe breakage) because
a developer started using new key before all servers could sync it.

-- 
Best regards,
Michał Górny

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to