EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  Index 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
<== Date ==> <== Thread ==>

Subject: Re: Changed source archive of StreamDevice release 2.8.22
From: Michael Davidsaver via Tech-talk <tech-talk at aps.anl.gov>
To: NICOLE Remi <remi.nicole at cea.fr>
Cc: "tech-talk at aps.anl.gov" <tech-talk at aps.anl.gov>
Date: Fri, 25 Nov 2022 09:17:57 -0800
On 11/24/22 07:38, NICOLE Remi via Tech-talk wrote:
But it seems weird to me that GitHub "reuploaded" the tarball, despite
GitHub saying the release was made in 2021-11-11.

It also feels weird that a source tarball of a fixed tagged version is
not itself "fixed". This, to me, feels like a security issue.

imo. concerns of this sort are a good reason to avoid relying on github.com
specific behavior like the automatic .tar/.zip file creation.

With epics-base, and my own projects, I'm trying to use PGP signed tags.
Which can be verify independently of github.com (or any forge site).

eg.

$ git clone --depth 1 --branch 1.0.1 https://github.com/mdavidsaver/pvxs.git
...
$ cd pvxs
$ git tag -v 1.0.1
object 6ee82fac6533d6551b18aa489cb263adc1333018
type commit
tag 1.0.1
tagger Michael Davidsaver <mdavidsaver at gmail.com> 1665862720 -0700

1.0.1
gpg: Signature made Sat 15 Oct 2022 12:38:40 PM PDT
gpg:                using RSA key 63245DAE9C6E10DBB4E923AB9401E6CB3D7F18EA
gpg:                issuer "mdavidsaver at gmail.com"
gpg: Good signature from "Michael Davidsaver <mdavidsaver at gmail.com>" [ultimate]
gpg:                 aka "Michael Davidsaver <mdavidsaver at ospreydcs.com>" [ultimate]



fyi. my primary key is 5C159E669D69E2D4C4E74E540C8E1C8347330CFB

https://keys.openpgp.org/vks/v1/by-fingerprint/5C159E669D69E2D4C4E74E540C8E1C8347330CFB

Of course, with current state of the PGP key server system, managing keys
is even more of a challenge than previously...

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


Replies:
Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
References:
Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk

Navigate by Date:
Prev: Re: EPICS nfs mount issues Michael Davidsaver via Tech-talk
Next: mca R7-10 available Mark Rivers via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
Navigate by Thread:
Prev: Re: Changed source archive of StreamDevice release 2.8.22 Zimoch Dirk (PSI) via Tech-talk
Next: Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024 
ANJ, 30 Nov 2022 Valid HTML 4.01! · Home · News · About · Base · Modules · Extensions · Distributions · Download ·
· Search · EPICS V4 · IRMIS · Talk · Bugs · Documents · Links · Licensing ·