From: Joseph Parmelee <hidden> Date: 2016-06-15 22:52:07
Hello all:
Under the present circumstances, and particularly considering the
sensitivity of the git code itself, I would suggest that you implement
signed detached digital signatures on all release tarballs. Just a crypto
hash by itself, however strong, does not protect against man-in-the-middle
attacks.
Joseph