EPICS Controls Argonne National Laboratory

Experimental Physics and
Industrial Control System

1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  2025  2026  Index 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  2025  2026 
<== Date ==> <== Thread ==>

Subject: Re: Changed source archive of StreamDevice release 2.8.22
From: Michael Davidsaver via Tech-talk <[email protected]>
To: NICOLE Remi <[email protected]>
Cc: "[email protected]" <[email protected]>
Date: Fri, 25 Nov 2022 09:17:57 -0800
On 11/24/22 07:38, NICOLE Remi via Tech-talk wrote:
But it seems weird to me that GitHub "reuploaded" the tarball, despite
GitHub saying the release was made in 2021-11-11.

It also feels weird that a source tarball of a fixed tagged version is
not itself "fixed". This, to me, feels like a security issue.

imo. concerns of this sort are a good reason to avoid relying on github.com
specific behavior like the automatic .tar/.zip file creation.

With epics-base, and my own projects, I'm trying to use PGP signed tags.
Which can be verify independently of github.com (or any forge site).

eg.

$ git clone --depth 1 --branch 1.0.1 https://github.com/mdavidsaver/pvxs.git
...
$ cd pvxs
$ git tag -v 1.0.1
object 6ee82fac6533d6551b18aa489cb263adc1333018
type commit
tag 1.0.1
tagger Michael Davidsaver <[email protected]> 1665862720 -0700

1.0.1
gpg: Signature made Sat 15 Oct 2022 12:38:40 PM PDT
gpg:                using RSA key 63245DAE9C6E10DBB4E923AB9401E6CB3D7F18EA
gpg:                issuer "[email protected]"
gpg: Good signature from "Michael Davidsaver <[email protected]>" [ultimate]
gpg:                 aka "Michael Davidsaver <[email protected]>" [ultimate]



fyi. my primary key is 5C159E669D69E2D4C4E74E540C8E1C8347330CFB

https://keys.openpgp.org/vks/v1/by-fingerprint/5C159E669D69E2D4C4E74E540C8E1C8347330CFB

Of course, with current state of the PGP key server system, managing keys
is even more of a challenge than previously...

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


Replies:
Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
References:
Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk

Navigate by Date:
Prev: Re: EPICS nfs mount issues Michael Davidsaver via Tech-talk
Next: mca R7-10 available Mark Rivers via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  2025  2026 
Navigate by Thread:
Prev: Re: Changed source archive of StreamDevice release 2.8.22 Zimoch Dirk (PSI) via Tech-talk
Next: Re: Changed source archive of StreamDevice release 2.8.22 NICOLE Remi via Tech-talk
Index: 1994  1995  1996  1997  1998  1999  2000  2001  2002  2003  2004  2005  2006  2007  2008  2009  2010  2011  2012  2013  2014  2015  2016  2017  2018  2019  2020  2021  <20222023  2024  2025  2026 
ANJ, 19 Mar 2026 · Home · News · About · Talk · Base · Modules · Extensions ·
· Distributions · Download · Documents · Links · Licensing ·