Expose changes file link in PPAs

Bug #270957 reported by Julian Edwards
2
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
High
Celso Providelo

Bug Description

In PPAs, links to changes files were removed as a poor hack to not obviously expose signed changes files to try and remove the danger of replay attacks.

Now that changes files are always stripped of signatures, we can put the link back in the PPA package listing.

This is requested by the security team to make their life easier when unembargoing from their private PPA.

Tags: lp-soyuz
Changed in soyuz:
importance: Undecided → High
milestone: none → 2.1.9
status: New → Triaged
Celso Providelo (cprov)
Changed in soyuz:
assignee: nobody → cprov
status: Triaged → In Progress
Celso Providelo (cprov)
Changed in soyuz:
milestone: 2.1.9 → 2.1.10
Revision history for this message
Celso Providelo (cprov) wrote :

RF 7050

Changed in soyuz:
status: In Progress → Fix Committed
Celso Providelo (cprov)
Changed in soyuz:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.