[MacPorts] #56034: Move binary archive signing public key to ports tree

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[MacPorts] #56034: Move binary archive signing public key to ports tree

MacPorts
#56034: Move binary archive signing public key to ports tree
-------------------------+-----------------------------
 Reporter:  neverpanic   |      Owner:
     Type:  enhancement  |     Status:  new
 Priority:  Normal       |  Milestone:  MacPorts Future
Component:  base         |    Version:
 Keywords:               |       Port:
-------------------------+-----------------------------
 The binaries we build are associated with the ports tree they were built
 from. If there were multiple ports trees configured in your installation,
 they should not be able to sign each other's archives, so a signing public
 key should be a property of a ports tree, rather than being shipped with
 base as we currently do.

 In the long run, adding a new ports tree should be simplified by offering
 a new command, and this command should prompt users to trust this key.

--
Ticket URL: <https://trac.macports.org/ticket/56034>
MacPorts <https://www.macports.org/>
Ports system for macOS