-
-
Notifications
You must be signed in to change notification settings - Fork 32.2k
Closed
Labels
docIssues and PRs related to the documentations.Issues and PRs related to the documentations.good first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.metaIssues and PRs related to the general management of the project.Issues and PRs related to the general management of the project.securityIssues and PRs related to security.Issues and PRs related to security.toolsIssues and PRs related to the tools directory.Issues and PRs related to the tools directory.
Description
EDIT:
We now generate detached signatures for all release lines. There is no documentation on how to verify this. An update to the Readme would be great!
Original
The current process for verifying releases is outputting a warning
gpg: Signature made Thu May 5 17:56:43 2016 CDT using RSA key ID 4C206CA9
gpg: Good signature from "Evan Lucas <[email protected]>" [ultimate]
gpg: aka "Evan Lucas <[email protected]>" [ultimate]
gpg: WARNING: not a detached signature; file 'SHASUMS256.txt' was NOT verified!
A script to verify and output is included in this gist
Metadata
Metadata
Assignees
Labels
docIssues and PRs related to the documentations.Issues and PRs related to the documentations.good first issueIssues that are suitable for first-time contributors.Issues that are suitable for first-time contributors.metaIssues and PRs related to the general management of the project.Issues and PRs related to the general management of the project.securityIssues and PRs related to security.Issues and PRs related to security.toolsIssues and PRs related to the tools directory.Issues and PRs related to the tools directory.