Menu

#66 Downloads are not signed

open
nobody
None
6
2012-10-08
2011-02-19
John Doe XI
No

Any compromise of the SourceForge mirror network could result in malicious alteration of Joda-Time downloads.

Discussion

  • Stephen Colebourne

    Perhaps so, but most people get code these days by maven repos which are signed. If I can do so easily, I'll sign the next version. If i can't do it easily, I'm afraid I won't go hunting to make it happen.

     
  • John Doe XI

    John Doe XI - 2011-02-20

    Thanks. Would you accept a build.xml patch?

     
  • Stephen Colebourne

    Patches are now accepted via GitHub pull requests. Only maven is now supported as a build system.

     

Log in to post a comment.