Re: Signing Releases And Security

2009-02-21 Thread Oleg Gusakov
Jason van Zyl wrote: If you create a set of binaries that have checksums and are signed it doesn't much matter how you produced the release. I mentioned the Ant tasks or using Maven itself as that's generally a good way to make a release. We'll probably make something with Mercury to provid

Re: Signing Releases And Security

2009-02-21 Thread Jason van Zyl
On 21-Feb-09, at 3:05 PM, Robert Burrell Donkin wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 jason's recently posted (http://mail-archives.apache.org/mod_mbox/incubator-general/200902.mbox/%3cea7c752b-2f67-4329-b0c5-35ccff853...@sonatype.com%3e ) a warning about tightening up release

Signing Releases And Security

2009-02-21 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 jason's recently posted (http://mail-archives.apache.org/mod_mbox/incubator-general/200902.mbox/%3cea7c752b-2f67-4329-b0c5-35ccff853...@sonatype.com%3e) a warning about tightening up release verification. i think that this is generally a good thing. i