29 May
2022
29 May
'22
9:46 p.m.
On 30/5/22 06:25, Jonas Witschel wrote:
Nevertheless I would love to see more (ideally all) packages using pinned tag object hashes over tag names, which I think would provide a tangible security benefit.
I thought this was already the standard. There were lots of bug reports (and a todo list?) to remove people using a tag a while back. Is there just a lack of detailed PKGBUILD guidelines? Allan