Feature Requests
New / Open / Unreviewed

Tip: HTTP repositories are not necessarily insecure

My HTTP repositories are marked as insecure in Patchmon, but they just use a different system of verifying releases with gpg keys. This is normal for - at least Debian based - Linux distributions, as this allows for HTTP caching layers in between to speed up deployment, while offering the same validation benefits due to the signatures attached to the packages.

Would you consider denoting GPG backed repositories as secure too?

Also see https://www.debian.org/doc/manuals/securing-debian-manual/deb-pack-sign.en.html for more info.

1 Comment

Posting anonymously

9technologygroup·9 months ago

Hey,

I do agree that there needs to be better terminology of how this is shown and for it to take into account gpg etc.

I will look into this and how we can enhance it.

Thank you
iby___

Posting anonymously