On Tue, Oct 05, 2010 at 05:49:31PM -0700, Zac Medico wrote:
> On 10/05/2010 05:26 PM, Robin H. Johnson wrote:
> > On Tue, Oct 05, 2010 at 05:53:50PM -0400, James Cloos wrote:
> >> Have portage note in the ebuild log what was signed, by what key, and
> >> whether the sigs were true.
> > zmedico: can we include this in the repoman commit sig?
> 
> Sure. Currently, repoman only signs the Manifest files in the ebuild
> directories. For single package commits, that's just one file. However,
> it's possible to do category-level or even full-repo level commits,
> though they're relatively rare. For these cases we'd be listing all the
> Manifest files that changed.
Sorry, I should have clarified. I was in favour of including the signing
key in the repoman commit message. The list of changed files is an
intrinsic property of the commit, so we don't need to duplicate it in
the commit message.

'(Signed Manifest commit)' - alter that to include the signing key env var.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : [email protected]
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

Attachment: pgpOMrwbpCGv7.pgp
Description: PGP signature

Reply via email to