https://bugzilla.redhat.com/show_bug.cgi?id=1272235
--- Comment #2 from Miroslav Suchý msuchy@redhat.com --- (In reply to Zbigniew Jędrzejewski-Szmek from comment #1)
https://bugzilla.redhat.com/show_bug.cgi?id=1246701 is about including more Fedora keys in fedora-repos.
Interresting. But still it will miss all others (centos/epel/rpmfusion...) I can add those old keys too.
I think it is very useful and increases security of various cross-distro installation. I wonder though whether not to remove Fedora and EPEL keys from this, since they will be included in fedora-repos, or maybe to add a check to make sure that they are identical in both packages.
bug 1246701 speaks just about old fedora keys, not about epel IIRC.
Regarding packaging:
- why not use a github tarball directly? It's much nicer than to force a git
clone and additional steps.
Because github tarball checksum was not stable in past (not sure if this changed recently). Also the URL is changing nearly each year. At least the URL we should use as suggested by Fedora Guidelines. And I do not use or create tar.gz at all. I just wrote tito --srpm and it will craft (binary identical) tar.gz for me.
- GPL, seriously? I'm all for GPL, but in this case CC-0 seems a much better
choice. After all, this should be freely copied.
Good point. License changed to CC-0.
Spec URL: http://miroslav.suchy.cz/fedora/distribution-gpg-keys.spec SRPM URL: http://miroslav.suchy.cz/fedora/distribution-gpg-keys-1.2-1.fc22.src.rpm