Something needs to be done as it is unacceptable to let Joe Random upload into the repo. Signing is a good start.

Erdfelt, Joakim wrote:

Having an app to do uploads: +1
Allowing anyone to load artifacts with no security measures: -googleplex



Should we consider having people/groups/organizations register as uploaders, with a security key that they sign their uploaded archives withwith?


Or is this just too much effort for little bang for the buck?

/* Joakim Erdfelt - Cingular Wireless */






--------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]



Reply via email to