On 30/5/22 06:25, Jonas Witschel wrote:
Nevertheless I would love to see more (ideally all) packages using pinned tag
object hashes over tag names, which I think would provide a tangible security
benefit.

I thought this was already the standard. There were lots of bug reports (and a todo list?) to remove people using a tag a while back.

Is there just a lack of detailed PKGBUILD guidelines?

Allan

Reply via email to