
| Msg # 184 of 15094 on ZZLI4416, Saturday 10-03-25, 1:16 |
| From: SEAN WHITTON |
| To: IAN JACKSON |
| Subj: Bug#1115852: git-debpush: retain upstrea |
From: spwhitton@spwhitton.name
Hello,
On Sat 20 Sep 2025 at 05:05pm +01, Ian Jackson wrote:
> pAndrew Bower writes ("Bug#1115852: git-debpush: retain upstream tag for
post
> hoc verification"):
>> It would be nice if the shallow git clone (*.git.tag.xz) retained
>> the signature of upstream tags as it does the signature for the
>> debian tag in order to allow the provenance of the upstream code to
>> be verified after upload.
>
> Hi. Thanks for your interest. We agree with your objectives.
>
> I think this is more or less a duplicate of #1110269 "tag2upload (and
> dgit?) should deposit upstream tags". Since we (the dgit team) think
> that git is primary, we think this should be recorded as git objects.
> I'm pretty sure we don't want to extend the .git.tar.xz thing which
> exists only because of our political compromise with ftpmaster.
I very much agree, let's not extend the .git.tar.xz, let's fix that
other bug.
--
Sean Whitton
--=-=-Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQJNBAEBCgA3FiEEm5FwB64DDjbk/CSLaVt65L8GYkAFAmjeYb8ZHHNwd2hpdHRv
bkBzcHdoaXR0b24ubmFtZQAKCRBpW3rkvwZiQI0UEACD0ULemFFj2PF2qDtYbGio
3YGvzV7IfI0MTITUBgzDKp+LewXg1h/O/4SXxrHNkY4mIe/tvzewmMN4WZ1Wo9zd
7/W9DASRD7lQUVA7x0MUTa3sj7DYoVX8uvXL2pveNP8Elon6jUOwpqGrkZLBZP8q
R025kzSbxsj74uXclZx1vC8JtSgQzft42uqWbQe4lT7OH9/Vn6ZEaBmZoPyKtjc7
QHGCir6TlwqS+Fyh3rBctpN+P0cmmv+Gjh9SbkYFg48hOjNUnmf7tOJymxGSPJvq
foGqDILl3OXuUuhXFsTXMy9cTOMB+//yM8swHoxTDcXOg7VgpeUhcr+aHc3ws6KL
Ih1A9n5y1l7pcbmzsfde5ttvfGBKS2VKE2tbRq1CiKKIHIPvyWoObtS050vCx3yJ
VtH9OtqH2OPD/QsnJW0x0j8iizn+kUFxuQfa0Zk2qC6OyCiRfWvJbdgJRQyYPQXI
eo5UPxQlac1+yVjyI9G5stcjT+0N0SHc1/hiYtIudl4+jDowCK18QBMwD3XvLPli
H77v+4pf04FddvrFGhqeJsVDvbiLQKcWyDv5d1AScAHwpXwn6FcNyRY1OuxEXjtv
AHgfTm1wXnFEqYiruzrpnuAxZK7Nc6XMiS92hLoW+a6gh3djxdKw+Xcvtj330qut
k3f4V/1lc4lth8FI0A4Vsg==ckRf
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: you cannot sedate... all the things you hate (1:229/2)
|
328,117 visits
(c) 1994, bbs@darkrealms.ca