emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Proposal to include obligatory PGP verification of packages from any


From: Jean Louis
Subject: Re: Proposal to include obligatory PGP verification of packages from any repository
Date: Mon, 19 Oct 2020 20:47:45 +0300
User-agent: Mutt/1.10.1 (2018-07-13)

* Stefan Monnier <monnier@iro.umontreal.ca> [2020-10-19 20:31]:
> > verified, I tried installing from ELPA, but did not see any
> 
> Side note: "ELPA" is the name of the protocol/infrastructure.
> So now I don't know if you installed from Mermelada, GNU ELPA, MELPA, or
> yet some other ELPA archive.

Alright I understood it so from info document.

When enabled, that variable we spoke about that should be T to verify
packages, it is I assume general for any package archive. So I have
tried installing some from ELPA and did not see any difference.

By the way, Marmelade is not eatable any more.

There are just few well known, ELPA, Org and MELPA.

It would be good that package authors start publishing their own
repositories to decentralize and ensure better of security. I would
trust some authors more if I am getting their packages from their
domain, signed by their keys.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]