Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document PGP release signature usage #116556

Open
maltfield opened this issue Mar 10, 2024 · 1 comment
Open

Document PGP release signature usage #116556

maltfield opened this issue Mar 10, 2024 · 1 comment
Labels
docs Documentation in the Doc dir

Comments

@maltfield
Copy link

maltfield commented Mar 10, 2024

Expected behaviour

When I go to download the latest version of python for Windows, I should also see instructions on how to verify the authenticity of the file after download and before install. Or, at least, a link to the document that describes this.

Actual behaviour

I see no mention about cryptographic authenticity verification on the download page

Steps to reproduce

  1. Go to https://www.python.org/downloads/release/python-3122/
  2. ???
  3. Get confused and open ticket

Additional Context

The download page links to the GPG signature, but this is useless without the key. Any page that references GPG signatures should at least link to a page that tells the user how they can get the authentic fingerprint/public key of the official release signing key.

I would recommend adding this link to the More Resources section and/or making the GPG heading of the table itself a link, as is the case with its adjacent Sigstore heading in the table.

@maltfield maltfield added the docs Documentation in the Doc dir label Mar 10, 2024
@hugovk
Copy link
Member

hugovk commented Mar 10, 2024

The main downloads https://www.python.org/downloads/ has a section on "OpenPGP Public Keys".

I would recommend adding this link to the More Resources section and/or making the GPG heading of the table itself a link, as is the case with its adjacent Sigstore heading in the table.

Agreed, let's add a link from "GPG" in the heading to https://www.python.org/downloads/. It would be good to add an anchor so we can link directly to something like https://www.python.org/downloads/#gpg

The code for this is in https://github.com/python/pythondotorg (please can someone transfer this issue?). For reference:

cc @sethmlarson

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs Documentation in the Doc dir
Projects
None yet
Development

No branches or pull requests

2 participants