mesos-reviews mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Benjamin Bannier <benjamin.bann...@mesosphere.io>
Subject Re: Review Request 65905: Used SHA512 for release file checksums.
Date Mon, 05 Mar 2018 17:03:02 GMT


> On March 5, 2018, 5 p.m., James Peach wrote:
> > Dis you consider switching to `sharsum(1)` so that users can also use `shasum` to
verify the signature? I couldn't find a way to get `gpg` to verify the signature ...

Great point, updated the patch.


- Benjamin


-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/65905/#review198629
-----------------------------------------------------------


On March 5, 2018, 6:02 p.m., Benjamin Bannier wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/65905/
> -----------------------------------------------------------
> 
> (Updated March 5, 2018, 6:02 p.m.)
> 
> 
> Review request for mesos, Kapil Arya, Till Toenshoff, and Vinod Kone.
> 
> 
> Repository: mesos
> 
> 
> Description
> -------
> 
> Apache now requires SHA checksum files instead of the previously
> required MD5, see the [signing recommendations](1). This patch updates
> the Mesos vote and release tooling to accommodate that change in
> policy. We use SHA512 as recommended in the [Apache SHA checksum
> FAQ](2).
> 
> We also fix the format of the produced digest file to be compatible
> with `sha512sum` to ease automatic release verification.
> 
> [1]: http://www.apache.org/dev/release-distribution#sigs-and-sums
> [2]: http://www.apache.org/dev/release-signing#sha-checksum
> 
> 
> Diffs
> -----
> 
>   support/release.sh 3aeda92e6bd48683cf609fa527633cd47b9f7dce 
>   support/vote.sh 649eebc6b5fe1b3783ae0c2c1706f1349ddc436c 
> 
> 
> Diff: https://reviews.apache.org/r/65905/diff/3/
> 
> 
> Testing
> -------
> 
> 
> Thanks,
> 
> Benjamin Bannier
> 
>


Mime
  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message