Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Portage security?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
reddragon
n00b
n00b


Joined: 04 Apr 2017
Posts: 24

PostPosted: Tue Apr 25, 2017 11:26 am    Post subject: Portage security? Reply with quote

i read about how webrsync-gpg can validate a snapshot.

how does emerge handle https and sftp sorce code links in ebuilds?

there are still alot of http and ftp links to sourecode in ebuilds,

should i be concerned?
Back to top
View user's profile Send private message
Apheus
Guru
Guru


Joined: 12 Jul 2008
Posts: 418

PostPosted: Tue Apr 25, 2017 11:30 am    Post subject: Reply with quote

The validated snapshot contains "Manifest" text files with checksums for every associated file, including ebuilds and distfiles. These are checked on fetch and on unpack. Emerge errors out if the checksum check fails.
_________________
My phrenologist says I'm stupid.
Back to top
View user's profile Send private message
reddragon
n00b
n00b


Joined: 04 Apr 2017
Posts: 24

PostPosted: Tue Apr 25, 2017 11:38 am    Post subject: Reply with quote

thats excellent news :)
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum