Re: [gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread Brian Dolbec
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 16 Jul 2015 23:06:03 -0400 NP-Hardass wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On 07/16/2015 09:25 PM, Brian Dolbec wrote: > > On Thu, 16 Jul 2015 21:13:09 -0400 NP-Hardass > > wrote: > > > >> -BEGIN PGP SIGNED

Re: [gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread NP-Hardass
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 07/16/2015 09:25 PM, Kent Fredric wrote: > On 17 July 2015 at 13:13, NP-Hardass > wrote: >> Additionally, I feel that a signature is a means of acknowledging >> that a package has been looked over, and that developer has >> stated that they appro

Re: [gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread NP-Hardass
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 07/16/2015 09:25 PM, Brian Dolbec wrote: > On Thu, 16 Jul 2015 21:13:09 -0400 NP-Hardass > wrote: > >> -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 > >> Not sure if this has been covered in some of the rather long >> chains of late, but I wa

Re: [gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread Brian Dolbec
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Thu, 16 Jul 2015 21:13:09 -0400 NP-Hardass wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Not sure if this has been covered in some of the rather long chains of > late, but I was thinking about GPG signing, and how the proposed

Re: [gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread Kent Fredric
On 17 July 2015 at 13:13, NP-Hardass wrote: > Additionally, I feel that a signature is a means of acknowledging that > a package has been looked over, and that developer has stated that > they approve of the existing state That much is somewhat implied by a developer owning a commit. Because in

[gentoo-dev] Git, GPG Signing, and Manifests

2015-07-16 Thread NP-Hardass
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Not sure if this has been covered in some of the rather long chains of late, but I was thinking about GPG signing, and how the proposed workflow requires every developer to sign their commits. Currently, it's advised that every manifest be signed.