Chris Lamb: > Ximin Luo wrote: > >> This minimal solution still depends on 3rd-party services being available to >> host the files. A much better solution is for the FTP archive to *also* store >> the signed buildinfo files, somewhere safe that can be recovered when needed. > > Totally ACK. Just to be clear, I was never proposing buildinfo.d.n be the > canonical source or location of .buildinfo files. Apologies if I gave that > impression. :) >
Oh, not at all, what I said was meant to be a general point, and more along the lines of "Debian archive should do this as well". I understand b.d.n is not making special claims. :) X -- GPG: ed25519/56034877E1F87C35 GPG: rsa4096/1318EFAC5FBBDBCE https://github.com/infinity0/pubkeys.git _______________________________________________ Reproducible-builds mailing list Reproducible-builds@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/reproducible-builds