openresty / openresty/openresty-packaging
Signed sources availability for packages
Nobody has claimed this yet.
- Dominant language
- Makefile
- Stars
- 187
- Forks
- 93
- PR merge metrics
- No merged PRs in 30d
Description
Hello,
The nice addition to the official packages would be the availability of the source packages, for RHEL and its clones, the *.src.rpm packages. This is a common best practice and is sometimes required by company guidelines for using open source. The source package should be signed in same manner like compiled package.
While I appreciate the convenience of compiled packages, having access to the source code packages allows for greater transparency, customization, and potential troubleshooting.
Then the repository file could be updated to contain the official source packages repository disabled by default (like EPEL and other repos).
Best,
Alex
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the repository file and packaging sources for the RHEL and clone targets. Check how compiled packages are built and signed, then determine how a disabled source-package repository would fit alongside the existing repositories. Done means signed *.src.rpm packages are published and the repository entry is disabled by default.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- linux
- Domain
- build-system, release
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100