GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    David Runge (dvzrv@chaos.social)'s status on Friday, 14-Jul-2023 19:49:54 JSTDavid RungeDavid Runge

    It seems we'll have a lot of "fun" with the #PyPi decision to remove signatures for sdist tarballs (https://blog.pypi.org/posts/2023-05-23-removing-pgp/) going forward.

    To scream into the void: Yes, PyPi, someone was using those signatures. Distro package maintainers secured user supply chains with it!

    I'm not looking forward to asking dozens of upstreams to host their signatures elsewhere (just stumbled across one case). Meanwhile #reproduciblebuilds is now broken for those packages.

    #ArchLinux #packagerlife #Python

    In conversationFriday, 14-Jul-2023 19:49:54 JST from chaos.socialpermalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: blog.pypi.org
      Removing PGP from PyPI - The Python Package Index
      from Donald Stufft
      PyPI has removed support for uploading PGP signatures with new releases.
    2. No result found on File_thumbnail lookup.
      forward.to - このウェブサイトは販売用です! - forward リソースおよび情報
      このウェブサイトは販売用です! forward.to は、あなたがお探しの情報の全ての最新かつ最適なソースです。一般トピックからここから検索できる内容は、forward.toが全てとなります。あなたがお探しの内容が見つかることを願っています!
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.