cvs commit: ports/devel/tmake Makefile distinfo

Dag-ErlingSmørgrav des at des.no
Tue Feb 17 05:09:16 PST 2004


Michael Nottebrock <michaelnottebrock at gmx.net> writes:
> On Tuesday 17 February 2004 13:49, Kris Kennaway wrote:
> > On Mon, Feb 09, 2004 at 02:07:32PM -0800, Kris Kennaway wrote:
> > > On Mon, Feb 09, 2004 at 05:36:08AM -0800, Michael Nottebrock wrote:
> > > >   Log:
> > > >   Fix distinfo, SIZEify.
> > > You forgot to summarize what changed.
> > I didn't see a followup to this.
> I have no idea what you expect me to write.

When the checksum of a distfile changes, there is a considerable risk
that someone may have trojaned the distfile.  As a port maintainer,
you are exptected to verify that this is not the case before updating
the checksum in distinfo.  You are also expected to summarize the
reason for the changed checksum in the commit message so that The Rest
Of Us[tm] can rest assured that you have indeed verified that the
distfile was not trojaned.

DES
-- 
Dag-Erling Smørgrav - des at des.no


More information about the cvs-all mailing list