Re: Security pitfalls of .tar.asc

2018-07-04 Thread Christian Hesse
"Jason A. Donenfeld" on Thu, 2018/07/05 02:54: > Hi list, > > The upcoming cgit 1.2 release will have support for attaching .asc > signatures to tarballs. Adding a .tar.xz.asc is straightforward and > works as expected. But there's also display logic for showing .tar.asc > signatures next to .tar

Security pitfalls of .tar.asc

2018-07-04 Thread Jason A. Donenfeld
Hi list, The upcoming cgit 1.2 release will have support for attaching .asc signatures to tarballs. Adding a .tar.xz.asc is straightforward and works as expected. But there's also display logic for showing .tar.asc signatures next to .tar.xz files. The intent is to do something like this: $ curl