repository is not signed

Bug #312175 reported by Kamil Páral
254
Affects Status Importance Assigned to Milestone
Ubuntu Tweak
Fix Released
Medium
Ding Zhou

Bug Description

Ubuntu Tweak repository is not signed with a PGP key. If it is, there is no information about it at:
http://ubuntu-tweak.com/downloads

The download page should mention which key is used to sign the packages and how to add them to the system.

Every time there is an upgrade to Ubuntu Tweak, the package managers warns the user that Ubuntu Tweak is an unsigned and therefore potentially dangerous package. It is true, someone may hack into your repository and replace the packages with his own. If you want to ensure people's trust, you have to sign your package. It is absolutely necessary for large-spread packages like Ubuntu Tweak.

Please sign your repository and give us information about that on your webpage. Thank you.

Revision history for this message
Ding Zhou (tualatrix) wrote :

Confirmed. Thanks!
I'll metion how to import the key.

Changed in ubuntu-tweak:
assignee: nobody → tualatrix
importance: Undecided → Medium
milestone: none → 0.4.5
status: New → Fix Committed
status: Fix Committed → Confirmed
Revision history for this message
Kamil Páral (kamil.paral) wrote :

This could be interesting for you:
https://bugs.launchpad.net/gscrot/+bug/312681

Ding Zhou (tualatrix)
Changed in ubuntu-tweak:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.