Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-9047

Releases should be GPG/PGP signed

    Details

    • Type: New Feature
    • Status: Resolved
    • Priority: Minor
    • Resolution: Incomplete
    • Component/s: core
    • Labels:
      None

      Description

      Either releases or the md5sum of the release should be signed for verification when pulling from a mirror

        Issue Links

          Activity

          Hide
          rtyler R. Tyler Croy added a comment -

          Added the interim board to this issue, while I'm not 100% on how we can do this.

          Show
          rtyler R. Tyler Croy added a comment - Added the interim board to this issue, while I'm not 100% on how we can do this.
          Hide
          danielbeck Daniel Beck added a comment -

          Is it not sufficient that the jar contents are signed?

          Show
          danielbeck Daniel Beck added a comment - Is it not sufficient that the jar contents are signed?
          Hide
          danielbeck Daniel Beck added a comment -

          No response to comment asking for additional information in two months, so resolving as Incomplete.

          Show
          danielbeck Daniel Beck added a comment - No response to comment asking for additional information in two months, so resolving as Incomplete.

            People

            • Assignee:
              rtyler R. Tyler Croy
              Reporter:
              mwalling Mark Walling
            • Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: