Embed Notice
HTML Code
Corresponding Notice
- Embed this notice@phnt Yeah AUR helpers I could understand them breaking and I consider that to be okay-ish, kind of which arch would have better support for community repos but well it's their choice.
ctrl-c pretty sure I never did, it's never a good idea, I do it on Gentoo sometimes but only when I know I could easily recover (and gentoo uses files instead of a database so less possible corruption).
> Which is a common problem if the system is left sitting for a month or two without updates.
I guess that's side-effect of how OpenPGP expires keys all to similarly as if they got revoked, ultimately making it hard to do slow key-rotation without ending up with keys valid for easily more than a year…
For packages I quite prefer the idea of rotating keys regularly and having some kind of limit placed on them not being system time but rather contextual time, like how OpenBSD uses a key per release (so roughly every 6 months), with the key of the next release being part of the release so sneaking an arbitrary next key seems pretty hard.