GNOME Bugzilla – Bug 120302
Request for OpenPGP signatures for releases.
Last modified: 2018-06-29 20:36:17 UTC
I was wondering at the likelihood of the latest, and subsequent, releases of GnuCash having a OpenPGP (i.e. GnuPG) digital signature (both for source and RPM releases). After the compromise of the GNU FTP server recently GNU has switched over to doing this. Looking at the archives it seems that both Derek and Linas are OpenPGP aware, and so could give additional insight... Cheers, S.
I have no idea how likely this is, but it would probably make sense to sign the tarballs. I'm targetting this as 2.0.0, but if it doesn't happen, then we'll just push it out to the next version.
Starting with the release of 2.0.0 the releases will now be signed. The signature file is in the sources dir with the file and the pubkey is there too. Closing this bug.
GnuCash bug tracking has moved to a new Bugzilla host. This bug has been copied to https://bugs.gnucash.org/show_bug.cgi?id=120302. Please update any external references or bookmarks.