@evilham You mean on installing cdist and verifying https://code.ungleich.ch/ungleich-public/cdist/uploads/dec9becf9b372ec1c48cb022ae8936aa/cdist-6.2.0.tar.gz.asc, right?
@evilham This signature is only valid if source tarball from tag release notes is used, or if tarball is created from the tag exactly the same as in release process. Installing from this source…
@poljakowski I think for the we'd need to generate our own keypair, put it likely into pass and then sign the resulting tar.xx. Generally speaking, a good idea.
@nico IIRC, keypair is already put into ungleich keystore.
I think we just need to document installing cdist from source tarball + signature.
closed via commit d5ac9ea348aa0ed640941232fbc2c783d95b8750
mentioned in commit d5ac9ea348aa0ed640941232fbc2c783d95b8750
(tried to assign this to myself but doesn't seem to be possible :-p. Just wanted to document this so I don't forget)
changed title from should __package update {-package -}index by default? to should __package update index by default?
so, you are talking about creating types __apt_unattended_upgrades and __dnf_automatic ?
i can take first one, because i have that on roadmap at work anyway.