www-repository mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Carlos Sanchez <car...@apache.org>
Subject Re: any issues related to the people.apache.org attack
Date Wed, 02 Sep 2009 14:27:46 GMT
I've got some sync mails (subject: [repo] /www/people.apache.org/repo/...)

last gpg check using Henk script is from Aug 26 with 3 bad signatures
from Wesley Wannemacher,
   http://people.apache.org/~henkp/repo/

BTW, I noticed the script only checks
/www/people.apache.org/repo/m2-ibiblio-rsync-repository/org/apache
should it be updated to check all /www/people.apache.org/repo/ ?
or at least /www/people.apache.org/repo/m2-ibiblio-rsync-repository/ ?

seems it checks just the last month, if timestamps are altered it may
not detect it?

On Wed, Sep 2, 2009 at 12:59 PM, Steve Loughran<steve.loughran@gmail.com> wrote:
> Looking at the people.apache.org writeup
> https://blogs.apache.org/infra/entry/apache_org_downtime_report
>
> I'm wondering if anyone could have got a malicious article into the
> main or snapshot repositories. Did any artifacts turn up during the
> day? Unsigned? It may be good to delete them
>

Mime
View raw message