That is being fixed "right now"[1], they seem to have most of it implemented (yes, obviously testing and documentation is still needed before its ready for non dev-branch release).
I just don't understand how a distro can call a package manager with unsigned packages ready for a stable branch. It's irresponsible, and if they don't care about that kind of basic need for a package manager, I don't want to put myself in a position where I'll discover (too late) what sort of other obvious oversights they've made.
Comments
Yes, I love package managers that don't provide a mechanism for signing code. I also love compromised mirrors.
That is being fixed "right now"[1], they seem to have most of it implemented (yes, obviously testing and documentation is still needed before its ready for non dev-branch release).
[1] https://bbs.archlinux.org/viewtopic.php?id=115528 (I haven't bothered checking the mailing list, but the latest forum post in that thread was two or three days ago)
I just don't understand how a distro can call a package manager with unsigned packages ready for a stable branch. It's irresponsible, and if they don't care about that kind of basic need for a package manager, I don't want to put myself in a position where I'll discover (too late) what sort of other obvious oversights they've made.