On 17 July 2013 00:19, Gary Gregory <[email protected]> wrote: > Should the keys file be in the email? Or a rev no of the keys file?
I don't think that's necessary. We just need to ensure that the key is in the file (and published to key servers). There are multiple copies of key entries; we just need to check the one at the time. Perhaps should include the revision of the dist/dev directory in SVN for completeness. > Gary > > On Jul 16, 2013, at 18:29, sebb <[email protected]> wrote: > >> We need to include the revision number as well as the SVN tag. >> We don't re-use tags (I hope!), but SVN does not guarantee tag >> immutability, so for completeness the revision is needed. >> It's easy enough to copy/paste from the commit mail. >> >> The KEYS file is needed so an outsider can easily check the sigs; it >> won't change. >> >> Having everything needed to check the release candidate present in the >> e-mail shows that the PMC is trying to ensure that the vote is clear >> and open. >> It should not be necessary for reviewers to go digging for URLs in >> order to complete their check. >> >> Also, then the historical record has everything together. >> >> I hope that makes sense to all? >> >> --------------------------------------------------------------------- >> To unsubscribe, e-mail: [email protected] >> For additional commands, e-mail: [email protected] >> > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
