LWN.net Logo

McRae: Pacman Package Signing - 4: Arch Linux

Back in March 2011, LWN examined package signing (or the lack thereof) in the Arch Linux distribution. Things have advanced considerably since then. Allan McRae has now posted the fourth in a series of articles about the adoption of signed packages in Arch. "The Arch repos have been gradually preparing for the package signature checking in pacman-4.0. Support for uploading PGP signatures with packages was added in April and was made mandatory from the beginning of November. As of today, 100% of the packages in the [core] repo and approximately 71% of [extra] and 45% of [community] are signed."
(Log in to post comments)

McRae: Pacman Package Signing - 4: Arch Linux

Posted Dec 19, 2011 16:59 UTC (Mon) by rleigh (subscriber, #14622) [Link]

It's great news to hear that proper GPG signing of all packages is getting close to completion, it being a long-standing defect in pacman.

Copyright © 2011, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds