Using https URL's for source files provides a little more security for those downloading the code. Packagers, of course, should be verifying the GPG signature files before pushing new releases to Fedora's source cache¹. While we're changing the source URL's, we might as well use the smaller tar.xz files which upstream provides. (This requires minor adjustments to the unpacking of prebuilt html and man tarballs; tar on el5 does not know how to automatically filter via xz.) ¹ Replace .xz with .sign for the signatures, which are made against the uncompressed tarballs.
4 lines
171 B
Plaintext
4 lines
171 B
Plaintext
b0219fcb6d73104361f4fbdba3741d00 git-2.7.4.tar.xz
|
|
d37654c45897afa4501fe7bc138b576f git-htmldocs-2.7.4.tar.xz
|
|
52507ee81f9aac0abf85160398cd3e81 git-manpages-2.7.4.tar.xz
|