Skip to content

Who verifies the sign of repos? #1237

Discussion options

You must be logged in to vote

One current example is that the BGS specifically must validate signatures when crawling repos from PDS instances. Signature validation will probably also be mandatory as part of account migrations between PDS hosts. As a general principle, when receiving content from another organization or party it is probably a good idea: an ACME Club AppView consuming from an ACME Club BGS might not bother re-verifying signatures (but maybe they should!).

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
1 reply
@yamarten
Comment options

Comment options

You must be logged in to vote
3 replies
@bnewbold
Comment options

Answer selected by bnewbold
@yamarten
Comment options

@bnewbold
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants