Re: revision control downloads

2022-03-23 Thread Ryan Schmidt
On Mar 23, 2022, at 16:31, Rainer Müller wrote: > On 22/03/2022 22.23, Ryan Schmidt wrote: > >> As I said we do already and have for a long time strongly discouraged using >> revision control systems for downloads. > > As these days most web frontends allow to download a tarball, we could >

Re: revision control downloads

2022-03-23 Thread Rainer Müller
On 22/03/2022 22.23, Ryan Schmidt wrote: > On Mar 22, 2022, at 13:08, Daniel J. Luke wrote: > >> On Mar 21, 2022, at 9:20 PM, Ryan Schmidt wrote: >>> Ports that fetch their sources from a revision control system do not enjoy >>> the protection of checksums. Although ports that fetch source from

Re: revision control downloads

2022-03-22 Thread Ryan Schmidt
On Mar 22, 2022, at 13:08, Daniel J. Luke wrote: > On Mar 21, 2022, at 9:20 PM, Ryan Schmidt wrote: >> Ports that fetch their sources from a revision control system do not enjoy >> the protection of checksums. Although ports that fetch source from a >> revision control system specify which tag

revision control downloads (was Re: Codesigning everything and combatting malicious code)

2022-03-22 Thread Daniel J. Luke
On Mar 21, 2022, at 9:20 PM, Ryan Schmidt wrote: > Ports that fetch their sources from a revision control system do not enjoy > the protection of checksums. Although ports that fetch source from a revision > control system specify which tag or commit hash to fetch, it is conceivable > that a