emacs-orgmode@gnu.org archives
 help / color / mirror / code / Atom feed
From: Radon Rosborough <radon.neon@gmail.com>
To: Emacs-orgmode@gnu.org
Subject: How can I obtain Org via HTTPS?
Date: Sun, 3 Dec 2017 22:46:49 -0800	[thread overview]
Message-ID: <CADB4rJFxTWTTPE0AOmKq0fU1TT_tWnDxx+SNFnWbjU4-zocb4w@mail.gmail.com> (raw)

Hello all,

It does not appear to be possible to obtain the Git repository for Org
via HTTPS or SSH, only via HTTP. I have checked the manual and
searched the Internet to see if there is a way, but no luck. I only
found an unanswered inquiry from earlier this year [1].

—Why is HTTPS/SSH necessary when Org releases are signed with GPG?
Well, only releases are signed. If you want to clone the development
version of Org, there appears to be no way to verify that it has not
been tampered with, since the clone was using an insecure protocol.

—Why do I care about this?
I maintain the package manager straight.el [2], which installs
packages by cloning their Git repositories. By default, the
development version of a package is installed. It would be
irresponsible to install packages via HTTP, so straight.el is forced
to install Org from the EmacsMirror [3] instead. This makes me
uncomfortable, since I would prefer to install packages from their
authoritative upstream sources—this makes contributing back to those
packages easier.

Have I missed something? Is it already possible to obtain Org
securely? If not, is making that possible a current goal of the
project? If not, what is the difficulty and can I help?

Best regards,
Radon Rosborough

[1]: http://lists.gnu.org/archive/html/emacs-orgmode/2017-03/msg00335.html
[2]: https://github.com/raxod502/straight.el
[3]: https://github.com/emacsmirror/org

             reply	other threads:[~2017-12-04  6:47 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-12-04  6:46 Radon Rosborough [this message]
2017-12-06 11:55 ` How can I obtain Org via HTTPS? Akater
2018-03-10 21:48 ` Bastien
2018-03-10 23:15   ` Radon Rosborough
2018-03-11  0:12     ` Bastien Guerry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

  List information: https://www.orgmode.org/

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=CADB4rJFxTWTTPE0AOmKq0fU1TT_tWnDxx+SNFnWbjU4-zocb4w@mail.gmail.com \
    --to=radon.neon@gmail.com \
    --cc=Emacs-orgmode@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).