Harald Sitter | 21 Jun 17:47 2016
Picon
Gravatar

Qt 5.6.1 and 5.7.0 buildtime version-check list

Alohas,

since with Qt 5.6.0 we've seen some KDE software have build time
improvements that are not neatly communicated such that one would
think to rebuild the software in question, I'd like to offer a list
for recently released 5.6.1 and 5.7.0 as well.

Please note that the list is non-exhaustive and in particular for
5.7.0 more additions are not entirely unlikely. To that end I'd also
like to refer you to [1] and [2] for reasonably complete lists on
both.

The following software should be rebuilt when picking up the affected
Qt versions.

# Qt 5.6.1
## frameworks
- kio (test only)
## plasma
- kwin (test only)
## apps
- kmail (shouldn't have runtime impact)
- messagelib

# Qt 5.7.0
# frameworks
- kauth (drops Qt 5.6 deadlock workaround)
# plasma
- kwin (QPA cchange)
# apps
(Continue reading)

Burkhard Lück | 17 Jun 13:49 2016
Picon

Review Request 128224: remove json, appdata and mimetype pos from frameworks tarball

This is an automatically generated e-mail. To reply, visit: https://git.reviewboard.kde.org/r/128224/

Review request for Release Team and David Faure.
By Burkhard Lück.
Repository: release-tools

Description

see summary

would make sense to share some common stuff between applications + frameworks

Diffs

  • pack_l10n.sh (2ba5dc5)

View Diff

_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Burkhard Lück | 17 Jun 13:42 2016
Picon

Review Request 128223: remove json, appdata and mimetype pos from applications tarball

This is an automatically generated e-mail. To reply, visit: https://git.reviewboard.kde.org/r/128223/

Review request for Release Team and Albert Astals Cid.
By Burkhard Lück.
Repository: release-tools

Description

see summary

Diffs

  • pack_l10n.sh (5afa5e8)

View Diff

_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Albert Astals Cid | 15 Jun 19:45 2016
Picon
Gravatar

KDE Applications 16.04.3 release dates

The planned tarball creation date for KDE Applications 16.04.3 is 7th July

I won't be near a computer that day, so i can either do it on the 6th or 
someone else has to take over the tarball creation + uploading to depot for 
packagers to get them.

Comments?

Cheers,
  Albert
_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Albert Astals Cid | 14 Jun 18:00 2016
Picon
Gravatar

www/sites/www

SVN commit 1461849 by aacid:

Release KDE Applications 16.04.2

CCMAIL: release-team <at> kde.org

 M  +0 -1      announcements/announce-applications-16.04.2.php  
 M  +6 -1      announcements/index.php  
 M  +2 -2      announcements/release_data.php  
 M  +110 -0    i18n/pt/www.inc  
 M  +6 -6      index.php  
 A             info/applications-16.04.2.php  
 A             info/source-applications-16.04.2.inc  

http://websvn.kde.org/?view=rev&revision=1461849
_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Albert Astals Cid | 12 Jun 03:09 2016
Picon
Gravatar

KDE Applications 16.08 Release Schedule

https://community.kde.org/Schedules/Applications/16.08_Release_Schedule

Discuss!

Cheers,
  Albert
_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Albert Astals Cid | 10 Jun 19:31 2016
Picon
Gravatar

KDE Applications 16.04.2 tarballs available for packagers

The tarballs for KDE Applications 16.04.2 are available at the usual location.

 

Release on tuesday.

 

Cheers,

Albert

 

_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Jonathan Riddell | 8 Jun 18:45 2016

Plasma now depends on Qt 5.6.1


I've updated Plasma Workspace in git master to require Qt 5.6.1 as
5.6.0 has problems.  Distros should packages Qt 5.6.1 or if they have
already patched 5.6.0 add a patch to Plasma Workspace to lower the
requirement.

Jonathan

_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
David Faure | 6 Jun 22:42 2016
Picon
Gravatar

KDE Frameworks 5.23.0

Dear packagers,

KDE Frameworks 5.23.0 has been uploaded to the usual place.
(not at the usual time though - I forgot about it Saturday... thanks to Alex 
Potashev for reminding me!)

New frameworks: none this time.

Public release next Saturday -- assuming I don't forget ;-).
(Recurring events added to my calendar, it should help)

Thanks for the packaging work!

-- 
David Faure, faure <at> kde.org, http://www.davidfaure.fr
Working on KDE Frameworks 5
attica v5.23.0-rc1
4824ebd25ec6da2b93bbdc052e2b02e78ef8b316
8a8cb27734b7efeba2a91adddfdc4863e8d5e7892e70c60afad5a4c09578b549  sources/attica-5.23.0.tar.xz
baloo v5.23.0-rc1
9452e74108f13f6bde2b9893b32298fbf31acbb0
4b32fc91a8f71b4ff5c0d7832ac6da41cdd8ea1a33594e905519565c4bbb6ed6  sources/baloo-5.23.0.tar.xz
bluez-qt v5.23.0-rc1
0e26dee0c68bdbbacbc034076a019f7dd5e2d4cb
89ece8748558eb3a8e081dc6eb4e7bd4104301373ce49d55d66b4bb197b933cb  sources/bluez-qt-5.23.0.tar.xz
breeze-icons v5.23.0-rc1
f9569f90c9ca4d927f60de7d5ead5ca6891395bc
e279cbba0d7556dad096db800a6a2b7d0e0e419c06df8f2bf2966f7bf49c98b2  sources/breeze-icons-5.23.0.tar.xz
extra-cmake-modules v5.23.0-rc1
bb0cbfd68e01a967012057919ac42865e632ab97
69ceba3e740295509d23b16420bc8357511a538da3e2d7a03f08662d218fed94  sources/extra-cmake-modules-5.23.0.tar.xz
frameworkintegration v5.23.0-rc1
4db227ed1372c54a790f3cfae069102825273e27
48b472cbdfc2407b68247dc40bcee8b6e9f951c2e20f97030c68f95f7d283b28  sources/frameworkintegration-5.23.0.tar.xz
kactivities v5.23.0-rc1
9b33648185f2e8d75cf3a1954c18c8dff9bf3569
82df07711f63db9881565e5e7be2ddf0945885123f34565bbd4cd571d9e9a1fa  sources/kactivities-5.23.0.tar.xz
kactivities-stats v5.23.0-rc1
c95092882e170bfefb8382f67ccb29173488d376
f172a8be312119ad8fddbd64c76519b37b6977445858be20eeca9aa5ac31bd65  sources/kactivities-stats-5.23.0.tar.xz
kapidox v5.23.0-rc1
00af9411e4f452d242c248d36d9f70ca64da6ed9
da711308793f6cb2a643f2c6771fe8635baf6355267ddc0e991af867cb4ab08b  sources/kapidox-5.23.0.tar.xz
karchive v5.23.0-rc1
e256a5522fc23279a74762a03b216df321a4d12c
3b3e310ae2aceae0513e809e4fc559bea5262cd26ecbe43071388cc1de5e30ef  sources/karchive-5.23.0.tar.xz
kauth v5.23.0-rc1
aa5d7b45a5e0e4372e601a9589ff642dbb3d280f
7788efd5710b939c302bb461681bcf47d55a39767ea15d5cdb760cf07c2fefa9  sources/kauth-5.23.0.tar.xz
kbookmarks v5.23.0-rc1
3816f021b2f59535439888ab413e0d7af04fdcae
74c6452ed80f99ef397e50cd6a488ac58186747090f5462790ccc6c9c0491ccc  sources/kbookmarks-5.23.0.tar.xz
kcmutils v5.23.0-rc1
f02a5decd51792a03cb7246c1127266dc66aacca
a0e8c8521d68704271748802d56418854be261ba7d3448e45fde220a248dc93a  sources/kcmutils-5.23.0.tar.xz
kcodecs v5.23.0-rc1
e8ac078407c79baf7e6bc2aa9b978931b3182257
ea572489454ea20258d1d844f7467bd0e5b8c8f7ccbddb89bedaf9bcccb0f4d6  sources/kcodecs-5.23.0.tar.xz
kcompletion v5.23.0-rc1
594fe85f34f897f8b1b65adf6421ed3732c3dd17
ff30cd08a09eb94c2c1508e29b44990380424a5251613d41c51a473dea80dfb0  sources/kcompletion-5.23.0.tar.xz
kconfig v5.23.0-rc1
f0aec4cb53b88d614676db36a1df03cd3752a5e2
629aa6ff4100c6af897420223f7afff718a80c3c357270e4a6aef87644f85ef1  sources/kconfig-5.23.0.tar.xz
kconfigwidgets v5.23.0-rc1
900a0b7248dfdd790afbdc48cc4f85d0f39ee465
915eb895a35a71e9e5707ad3d4becc83ee543a27df8293d712374dbd33707872  sources/kconfigwidgets-5.23.0.tar.xz
kcoreaddons v5.23.0-rc1
a470b2c601b7472fbb3313ea64cdc5d6a9cc2735
57940b097858007c014bda5c4917455cbdadbf2dab657cadc7748fb87d6d4108  sources/kcoreaddons-5.23.0.tar.xz
kcrash v5.23.0-rc1
849d95837c0e5abf673d937765e01356e0f53499
d165969c7adc406e04acf78253579019d19c1bbca5ab82ce257c70173994a314  sources/kcrash-5.23.0.tar.xz
kdbusaddons v5.23.0-rc1
046c7d23971f73d50bc3f684ac39739c65719f40
c65fdab67401609835ad6523789d0f9cac50f784ecf915bd897386ce214f75ae  sources/kdbusaddons-5.23.0.tar.xz
kdeclarative v5.23.0-rc1
84db52db6304d3decd2e640bfa522cf2334f2471
fba8b19971bfa72fc20bf79a324d0be85c7f728837ad7ef349c6a339d8f831ff  sources/kdeclarative-5.23.0.tar.xz
kded v5.23.0-rc1
317001a9df9693a16eedff31fee2b3b6184ee016
6372b92d37cb5ff0b4428767f1131ab3f979a750855823ee8ca69402dd126234  sources/kded-5.23.0.tar.xz
kdelibs4support v5.23.0-rc1
cfbe9b4299047fe075209321256777cbb0e12dc8
95a3e6096c26a7c7e1815e3d3020623323eeadf48f7c920c75540eeb14727984  sources/portingAids/kdelibs4support-5.23.0.tar.xz
kdesignerplugin v5.23.0-rc1
11d602ddf5711c11a8686ae44f82bf01b3390fbb
14aa080c3dbbbe60208d5b6262f0e17c5a1c943a7651c245d52e235898536509  sources/kdesignerplugin-5.23.0.tar.xz
kdesu v5.23.0-rc1
5fa05db2e7c29313fab12e3e6579efa7e39de138
0fc15f80b8d6dfeee3876909e37f99bc1adb488e6e9d230002bc0f4bb01a8e28  sources/kdesu-5.23.0.tar.xz
kdewebkit v5.23.0-rc1
16c5c8430f2af1968a1e0b05ec55f96a05cd33a0
73a4be6535b6d6389f747a3ef5544d122c49d29796688787576202786fc282d6  sources/kdewebkit-5.23.0.tar.xz
kdnssd v5.23.0-rc1
15b793bb047fd570b56d3a2f28b7d1774956e721
740356e4a37b66809d62493aa9dae16f34b77be89a719f1b8d5de1635460b145  sources/kdnssd-5.23.0.tar.xz
kdoctools v5.23.0-rc1
55f6a5b156e4b9b4ba7dec45b8d677a86fe8cb26
a0fedf272433204334204b220f4fed2c3ab64167e08ea004f74088645f7cf7c5  sources/kdoctools-5.23.0.tar.xz
kemoticons v5.23.0-rc1
1db486951e13284c1dd7024727814dc6ea4ed11f
bfc718bcc86cd9bdd8954b87c291d1bafdcf3ed3fe402d2095a71c009b3068aa  sources/kemoticons-5.23.0.tar.xz
kfilemetadata v5.23.0-rc1
05b868f7b7adea1f820e0f5b84b2e971eef481c2
fad84cbc477c36aa967a1f4facd7bfa6825346bdddae87b1fd9db64d9dc2688f  sources/kfilemetadata-5.23.0.tar.xz
kglobalaccel v5.23.0-rc1
551e9f4d159eb62079710f4ae0bf7aadb9cda7eb
6d99671a7cf9eb768b0adbd1698a6b74d612651f8acf433a9189c8583547fce7  sources/kglobalaccel-5.23.0.tar.xz
kguiaddons v5.23.0-rc1
84ba445927d76811145ca3e52e65282e17b709ad
234bc39d79a06ead5b586a84e60edd821093ff8b24b0c94f0a1db13379f31d2d  sources/kguiaddons-5.23.0.tar.xz
khtml v5.23.0-rc1
44c92b211c6a94276c248e79a2b798dc65466943
c3b70fbb5e8083792a1b0268a6500937bfec88c2b94a40557699db5ebbbaf747  sources/portingAids/khtml-5.23.0.tar.xz
ki18n v5.23.0-rc1
b8bcea894ca7fa6e00a749267e55b3d9cef7255b
5766c2ac116ad8eb2c33bc197db3c80337fc5d3de7245291ea0615173bef7b91  sources/ki18n-5.23.0.tar.xz
kiconthemes v5.23.0-rc1
9d41b866a8d5a293acd02a9299d931a0d10e1a0b
1e64d9d85400ff39e791bde727ba85b71a7d12b953548780e233984d43b8cfbf  sources/kiconthemes-5.23.0.tar.xz
kidletime v5.23.0-rc1
334b2c254c70b0a418401b449282ee8ab30f45e0
8c42545c0d89fdbf034054afb7b8ea87d85be3fd1d690b16dd66bdcf7aa39312  sources/kidletime-5.23.0.tar.xz
kimageformats v5.23.0-rc1
69154fea3abaf71001cfadf401a04ced8b4e9af0
d1b04d7a6cbaa426ebbcc9fecf0d326c703413db5227fc182016589497288d7b  sources/kimageformats-5.23.0.tar.xz
kinit v5.23.0-rc1
2a6b85a8ff50812c41a7a257bf407bcbb85ce299
c3d2e5fc2fa71e6d1d2cca2e5654f90cbe4d4dd5607898365e062d4471a48f7d  sources/kinit-5.23.0.tar.xz
kio v5.23.0-rc1
df519a3134d784e9b9cc34681228a44531a33b3d
3489ba9c45e587f6b8b542aea4608eeb21cdbca27ef37d9f45d4308da8fd32b5  sources/kio-5.23.0.tar.xz
kitemmodels v5.23.0-rc1
ce2ef0c69336be8ca80b6e3d123fa7507e53c2c2
2110aadb11449aa75b94327af9ed930259afea354b1b01b5ef82d042c877cfc5  sources/kitemmodels-5.23.0.tar.xz
kitemviews v5.23.0-rc1
83028c2c3c723782bcfc4f13d599592e354d81f9
77fde1a44e2526a51a08f2d438d42ebb59d9b7c3c2d574d546c1379b3574bca1  sources/kitemviews-5.23.0.tar.xz
kjobwidgets v5.23.0-rc1
46656e446b9b99b7b3f5f16922a5fa1e78ee3f2a
be950bed77571d916f745b25d264e554ee6ba8e2180cd3601ed27f4f3117e0b2  sources/kjobwidgets-5.23.0.tar.xz
kjs v5.23.0-rc1
17c5858c7f3457b430c659fe4b89f422dee778f1
57c16396c4d0cbf15cc682ab03c7baf96b6875875ab6cda9405a5084a2df6eab  sources/portingAids/kjs-5.23.0.tar.xz
kjsembed v5.23.0-rc1
35a271ead8c0a64b45a9d1aa19195878a78467c6
1f90fa3e0e259b92160899c151c83d21771511920b8f4af6d2df32a4da09606e  sources/portingAids/kjsembed-5.23.0.tar.xz
kmediaplayer v5.23.0-rc1
a9e1083205b3826516b86b002522533c99f68190
a7637369d7af7b4804922c6f518a7c730e4a24128457e8f480293f1812859274  sources/portingAids/kmediaplayer-5.23.0.tar.xz
knewstuff v5.23.0-rc1
d85823c53f61fa7b66a23f49cb98d2d35c86d25f
18d711b46f74863ccd8b323cd323029fb0c58c3e670b9b436658b13504b70066  sources/knewstuff-5.23.0.tar.xz
knotifications v5.23.0-rc1
751d28b6b692c567d202e666cf6412afcfb68632
db310b4e850cfe534a25b5b788914e3b1fb4a22cc1ed210eaf2968498375e68e  sources/knotifications-5.23.0.tar.xz
knotifyconfig v5.23.0-rc1
3ae611ff7440487810c977ce7b5158388b417216
ec71475175445878b8a0eefc908c5e0e66152c31ce7ab264cc607c13d6fac138  sources/knotifyconfig-5.23.0.tar.xz
kpackage v5.23.0-rc1
69452d98652ac21938a4ca6baae84b2944e2e88d
f580cea44608c0789eca2ccd901fa54d02acf1a70a6c0e676292a78cf3ffdec2  sources/kpackage-5.23.0.tar.xz
kparts v5.23.0-rc1
e5f37b850c3af720df13da2d664baf6f97a3034f
2e584c9904aaef4cffeedeb686ca9addfca25a3a118779d6a31ab02c62f4d705  sources/kparts-5.23.0.tar.xz
kpeople v5.23.0-rc1
caadaa5323fc1bdb2b98a8d12f0622386dd7c93e
5203af2ebcb78889f50ab8331a7a840f486fa501e0fb764e0481e9aa9fca3d14  sources/kpeople-5.23.0.tar.xz
kplotting v5.23.0-rc1
8c19ace83ce5b2c5b128fd09dfed3be10cbd0fbe
46b0d39298e6877c09c766e3a70f72a7aa6994c621674d630c5a35a656b622ec  sources/kplotting-5.23.0.tar.xz
kpty v5.23.0-rc1
fd1bd4962c59476396f6dc9251dbd7ebe1fa7e8c
b96d7b538c9970570822a1f119b04eb0518a9557fd2bb692ccc673dc40d9d96c  sources/kpty-5.23.0.tar.xz
kross v5.23.0-rc1
ee080bf2530f8807a18736d13c2e8a88f45a3276
8002a5102aa5f66bc0a24f534c319004adb0a011b1598c38742e3a367c49a668  sources/portingAids/kross-5.23.0.tar.xz
krunner v5.23.0-rc1
cb4e30fe6c6028cfc7dd903334f575a576a4a2a2
52ac6b5a7c99fa0cb9e776b06348511fe5373fc9acc2842be760c7ae60a2d9dd  sources/krunner-5.23.0.tar.xz
kservice v5.23.0-rc1
df198d29a79b10a28c83e3b4b84b85dbd66931fd
3836f73746a9fd099f6b078e5e456808ec0fef69d8710f5a7904b3d9c3976fce  sources/kservice-5.23.0.tar.xz
ktexteditor v5.23.0-rc1
8d1107f06cbc92489cc68d86c044db9ac6ead15d
08eca5054f7b696671407cb628a657b9736b363c6a1476e4dd37adb3e46a2f76  sources/ktexteditor-5.23.0.tar.xz
ktextwidgets v5.23.0-rc1
17988f2d42a56008b0d139f47b02c2e0b35f0bc9
898c25658315cb86cfae36cfcb879e02a2957fbd704f79551daf9fb08d9cfbd3  sources/ktextwidgets-5.23.0.tar.xz
kunitconversion v5.23.0-rc1
e15ff622b5f25707e5e18b766d33e4cd46ae8b67
8fda2eb4064c98d74be2ab8ddfc4f289a0d82238ba689054e3e2746db73d7f8e  sources/kunitconversion-5.23.0.tar.xz
kwallet v5.23.0-rc1
e24173492424746072b95d3cb207cdf869ccd3c2
eef55c2f07044deb229d7ce43cb1391c871de4545e88867ad8229589e77861a0  sources/kwallet-5.23.0.tar.xz
kwayland v5.23.0-rc1
72c8c6d56ba828236a0a56c469b7c2b887878edf
457da4cee13f4a13b01a06cebe23482105e8222d761f77c20a719fe731c741a5  sources/kwayland-5.23.0.tar.xz
kwidgetsaddons v5.23.0-rc1
f0d091e833702a96b42f0fb55e6de8f9564af980
544f7e8096bf926fd35285ae443ef7504a758d647225604e3c0a19f5cbab14a3  sources/kwidgetsaddons-5.23.0.tar.xz
kwindowsystem v5.23.0-rc1
b51071f32293ef33e2e431feb787cb22d443a9b2
5dd42aa08abc8a98f03972abaf8825f53a9a22edc34e8c7217945e165d5e02fe  sources/kwindowsystem-5.23.0.tar.xz
kxmlgui v5.23.0-rc1
477a20b59a2ad4992310fd8aa4fc2efdd3fd0669
f91202af22b13681759ff78098bc066263b74dd1662ab88df0caf79478c22e7d  sources/kxmlgui-5.23.0.tar.xz
kxmlrpcclient v5.23.0-rc1
dc8ef4c733dbb4ac4c904d107644f3af8053b2a8
99620f451c30fc4a85d88794753bd7e704bf8b89a76de049533bccfc17743857  sources/kxmlrpcclient-5.23.0.tar.xz
modemmanager-qt v5.23.0-rc1
2e7004d1d88e9b2c83e3786f0b11e4d51809057f
e99c36a09abe78289932ca24e689b0de21e32fd15280bffc0df4f3684ac75662  sources/modemmanager-qt-5.23.0.tar.xz
networkmanager-qt v5.23.0-rc1
6a0258ce7278190343a07d8fb927d96d3b740a5c
18910657cf12b0f4fca15ecc4dccf65e4507b2a2114dfd932215fd6c767552db  sources/networkmanager-qt-5.23.0.tar.xz
oxygen-icons5 v5.23.0-rc1
cd85f327fed773d210a9a164ba9341ecc4619f2d
ddff8c1f20f4182a118eebb0d89a188def246a92c2dc532aee52ad99655a2f92  sources/oxygen-icons5-5.23.0.tar.xz
plasma-framework v5.23.0-rc1
f5ff3a9dfae8efb8f4f00d2227fccf52848d2ac8
80294a22cd6c2eb4765bbce236f5a7b74a90c59481d8d4428c7addd9c96b2807  sources/plasma-framework-5.23.0.tar.xz
solid v5.23.0-rc1
be5a4cfb64919f5d8faf285653b55566d65ed73a
8a04f54b180cab8f0091a714cbff36b6b89ca3a62aa37119c046a05f1965df64  sources/solid-5.23.0.tar.xz
sonnet v5.23.0-rc1
8feecfd28c8601eee82576f3b28c07d0cd12f8e0
b14c6299e7b668fe18ed3f5991648e2daec79044c272d9ed46053961194de251  sources/sonnet-5.23.0.tar.xz
threadweaver v5.23.0-rc1
d2c5f7e8cd87ddfd8597202596efe5f416610343
3711dfee2edcecb4c86ad3924a4d3ec4709ba151134d51e2d7db98290d063427  sources/threadweaver-5.23.0.tar.xz
_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Albert Astals Cid | 3 Jun 16:02 2016
Picon
Gravatar

Re: tarball signing

El dijous, 2 de juny de 2016, a les 13:53:46 CEST, Harald Sitter va escriure:
> Ahoy
> 
> At last weekends' Munich sprint, Jonathan and I discussed the
> possibility of detached-signing our tarballs. Right now people have to
> go to some website, get checksums, and then verify the downloaded
> tarballs matches the checksums.
> This is not only terrible because it involves humans doing things, it
> is also terrible as there is no way to tell whether or not the data on
> the website is even authoritative, in particular for extragear where
> this information might not even be under https certification and even
> if it was who's to say the webserver hasn't been compromised.
> Add that our tarball mirrors are often distributing over http or ftp
> and getting an authoritative tarball is more luck than consistent
> checks.
> 
> And that is why we should sign our tarballs and we agreed to start
> doing that soonishy for Plasma tarballs (or rather: releasme in
> general) and would like to encourage everyone to build appropriate GPG
> signing tech into their release scripts. At the very least frameworks
> and apps would be beneficial to cover with signatures.
> It allows us to easily verify file integrity as well as file
> trustworthyness as either of the two not adding up would result in a
> verification failure.
> 
> So how's that work?
> Relevant starting documentation can be found at [1]
> 
> I would for example run
> $ gpg2 --digest-algo SHA512 --armor --detach-sign -o
> phonon-4.9.0.tar.xz.sig -s phonon-4.9.0.tar.xz
> 
> This generates a .sig file for the phonon 4.9 tarball.
> 
> Which I can then verify
> $ gpg2 -q --verify -q phonon-4.9.0.tar.xz.sig phonon-4.9.0.tar.xz; echo $?
> gpg: Signature made Don 02 Jun 2016 13:34:35 CEST using DSA key ID 72F23991
> gpg: Good signature from "Harald Sitter <apachelogger <at> ubuntu.com>"
> [ultimate]
> 
> Now then. In the grand scheme of things we'd only ship tarballs with a
> relevant sig in the same directory. A consumer of our tarballs (e.g. a
> linux distribution) would grab our tarball *and* the sig and ensure
> that the sig is an authoritatively trusted key (e.g. part of a keyring
> with trusted keys).
> If the verification succeeds the tarball is good to be used, if not
> human intervention is required to investigate.

Does that really fix anything if noone has my gpg key in the trusted/validated 
signatures area? How do they know it's me that signed the package and not some 
hacker that got access to the server and did sign the tarballs?

Cheers,
  Albert

> [1] https://www.gnupg.org/gph/en/manual/x135.html
> 
> HS
> _______________________________________________
> release-team mailing list
> release-team <at> kde.org
> https://mail.kde.org/mailman/listinfo/release-team

_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team
Aleix Pol | 2 Jun 15:48 2016
Picon
Gravatar

Kamoso 3.2 and purpose release

Hi,
I'd like to announce the Kamoso 3.2 and Purpose 1.1 release.

http://download.kde.org/stable/kamoso/3.2/src/kamoso-3.2.tar.xz.mirrorlist
http://download.kde.org/stable/purpose/purpose-1.1.tar.xz.mirrorlist

Here's a wiki with the tarballs. If you want to put instructions on
how to install it, that could be a good place.
https://userbase.kde.org/Kamoso/3.2

Thanks!
Aleix
_______________________________________________
release-team mailing list
release-team <at> kde.org
https://mail.kde.org/mailman/listinfo/release-team

Gmane