| 1 | GLEP: 57 |
1 | GLEP: 57 |
| 2 | Title: Security of distribution of Gentoo software - Overview |
2 | Title: Security of distribution of Gentoo software - Overview |
| 3 | Version: $Revision: 1.3 $ |
3 | Version: $Revision: 1.5 $ |
| 4 | Last-Modified: $Date: 2010/01/13 03:26:53 $ |
4 | Last-Modified: $Date: 2010/02/07 16:24:17 $ |
| 5 | Author: Robin Hugh Johnson <robbat2@gentoo.org> |
5 | Author: Robin Hugh Johnson <robbat2@gentoo.org> |
| 6 | Status: Draft |
6 | Status: Final |
| 7 | Type: Informational |
7 | Type: Informational |
| 8 | Content-Type: text/x-rst |
8 | Content-Type: text/x-rst |
| 9 | Created: November 2005 |
9 | Created: November 2005 |
| 10 | Updated: May 2006, October 2006, November 2007, June 2008, July 2008, October 2008, January 2010 |
10 | Updated: May 2006, October 2006, November 2007, June 2008, July 2008, October 2008, January 2010 |
| 11 | Post-History: December 2009 |
11 | Post-History: December 2009 |
|
|
12 | Approved: 18 January 2010 |
| 12 | |
13 | |
| 13 | Abstract |
14 | Abstract |
| 14 | ======== |
15 | ======== |
| 15 | This is the first in a series of 4 GLEPs. It aims to define the actors |
16 | This is the first in a series of 4 GLEPs. It aims to define the actors |
| 16 | and problems in the Gentoo software distribution process, with a strong |
17 | and problems in the Gentoo software distribution process, with a strong |
| … | |
… | |
| 334 | University of Arizona Technical Report TR08-02. Available online |
335 | University of Arizona Technical Report TR08-02. Available online |
| 335 | from: ftp://ftp.cs.arizona.edu/reports/2008/TR08-02.pdf |
336 | from: ftp://ftp.cs.arizona.edu/reports/2008/TR08-02.pdf |
| 336 | [C08b] Cappos, J et al. (2008). "Attacks on Package Managers" |
337 | [C08b] Cappos, J et al. (2008). "Attacks on Package Managers" |
| 337 | Available online at: |
338 | Available online at: |
| 338 | http://www.cs.arizona.edu/people/justin/packagemanagersecurity/ |
339 | http://www.cs.arizona.edu/people/justin/packagemanagersecurity/ |
|
|
340 | [#GLEPxx+2] Future GLEP on Developer Process security. |
|
|
341 | [#GLEPxx+3] Future GLEP on GnuPG Policies and Handling. |
| 339 | |
342 | |
| 340 | Copyright |
343 | Copyright |
| 341 | ========= |
344 | ========= |
| 342 | Copyright (c) 2005-2010 by Robin Hugh Johnson. This material may be |
345 | Copyright (c) 2005-2010 by Robin Hugh Johnson. This material may be |
| 343 | distributed only subject to the terms and conditions set forth in the |
346 | distributed only subject to the terms and conditions set forth in the |