On 02/09/2015 02:44 AM, Eliezer Croitoru wrote: > The other alternative to just trust you or distrust you is the > availability of the src.rpm package which will clarify for those who > knows how to look at them, how secure are these packages.
The .src.rpm package is there as well in the gf-testing-source repo. Peter