Verified Commit e6e914b3 authored by anarcat's avatar anarcat
Browse files

link to the openpgp signing issue

parent 420b2c75
Loading
Loading
Loading
Loading
+2 −1
Original line number Diff line number Diff line
@@ -1673,7 +1673,8 @@ code is hosted.

A good reference for OpenPGP verification is [this guix article](https://guix.gnu.org/blog/2020/securing-updates/)
which covers a few scenarios and establishes a pretty solid
verification workflow.
verification workflow. There's also a larger project-wide discussion
in [GitLab](howto/gitlab) [issue 81](https://gitlab.torproject.org/tpo/tpa/gitlab/-/issues/81).

We could use the [webhook](https://github.com/voxpupuli/puppet_webhook) system to have GitLab notify the Puppet
server to pull code.