You are not logged in.
Is it possible to configure pacman to download signatures for each package (as a discrete .sig file), and keep those in the cache directory?
Why do I want this?
My cache directory is a network share to which several machines have write permissions, and I would like to have a signature to check when downgrading a package to an older version, to secure them from manipulation. If I understand correctly, package PGP signatures are located in the database file, and the database file only contains entries for the most current packages.
Last edited by anacron (2020-09-06 15:58:14)
Offline
This is the case by default with no way to opt out in pacman-git and the upcoming pacman 6.0 beta.
Last edited by eschwartz (2020-09-06 15:50:49)
Managing AUR repos The Right Way -- aurpublish (now a standalone tool)
Offline
Sweet! ![]()
Offline