[Python-Dev] Signed packages (original) (raw)

martin at v.loewis.de martin at v.loewis.de
Sat Jun 23 14:03:10 CEST 2012


I'm surprised gpg hasn't been mentioned here. I think these are all solved problems, most free software that is signed signs it with the gpg key of the author. In that case all that is needed is that the cheeseshop allows the uploading of the signature.

For the record, the cheeseshop has been supporting pgp signatures for about ten years now. Several projects have been using that for quite a while in their releases.

Regards, Martin



More information about the Python-Dev mailing list