View previous topic :: View next topic |
Author |
Message |
reddragon n00b


Joined: 04 Apr 2017 Posts: 24
|
Posted: Tue Apr 25, 2017 11:26 am Post subject: Portage security? |
|
|
i read about how webrsync-gpg can validate a snapshot.
how does emerge handle https and sftp sorce code links in ebuilds?
there are still alot of http and ftp links to sourecode in ebuilds,
should i be concerned? |
|
Back to top |
|
 |
Apheus Guru

Joined: 12 Jul 2008 Posts: 422
|
Posted: Tue Apr 25, 2017 11:30 am Post subject: |
|
|
The validated snapshot contains "Manifest" text files with checksums for every associated file, including ebuilds and distfiles. These are checked on fetch and on unpack. Emerge errors out if the checksum check fails. _________________ My phrenologist says I'm stupid. |
|
Back to top |
|
 |
reddragon n00b


Joined: 04 Apr 2017 Posts: 24
|
Posted: Tue Apr 25, 2017 11:38 am Post subject: |
|
|
thats excellent news  |
|
Back to top |
|
 |
|