Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.
Bug 325039 - Should sign all builds and bundles
Summary: Should sign all builds and bundles
Status: RESOLVED FIXED
Alias: None
Product: WTP Releng
Classification: WebTools
Component: releng (show other bugs)
Version: 3.10   Edit
Hardware: PC Windows 7
: P3 normal (vote)
Target Milestone: 3.10.0   Edit
Assignee: David Williams CLA
QA Contact: David Williams CLA
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-09-11 19:35 EDT by David Williams CLA
Modified: 2018-06-29 15:30 EDT (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description David Williams CLA 2010-09-11 19:35:37 EDT
All builds we "promote" anyway. 

One problem is that once a jar is produced, and put in a p2 repo, if the version (even qualifier) doesn't change, then the new jar won't be "pulled" from the repo if it already exists. So, if someone has been "installing" from weekly I builds, then they would not pick up signed versions once we moved to S builds. 

Another, of course, is that some would say it's better to make each build, at least each build we test and promote, as much like the final build as possible. 

Also, we should sign test bundles too, since we make those available in our repos. Even though not widely downloaded, those that do (e.g. committers) deserve the same security protection that signing affords. 

All this signing will add considerable overhead to each build, so long term, we may want another type of "continuous build" (similar to old fashioned nightly) that are not signed ... but we need to make sure those are never promoted ... and then switch to I builds only on Thursdays (Wednesday evenings). 

For now, I'm going to simply turn on signing for I-builds and tests.
Comment 1 David Williams CLA 2011-05-25 22:31:33 EDT
doesn't seem like that much overhead ... we'll just always sign.