Skip to main content

in reply to daniel:// stenberg://

the only issue with BDFL is the problem of succession ... have you considered rotating/sharing out key rituals in curl eg. someone else manage a release every once in a while - for example ?
in reply to Jim Fuller

@jimfuller I have made sure that making a release is a matter of following the checklist in a public document, and in fact anyone can do that. It's just the signing with my key and the upload credentials to the server that makes it harder for anyone else to do it.
in reply to daniel:// stenberg://

perhaps have someone do all the other steps and you can bless it with your signing key ?
in reply to Jim Fuller

@jimfuller I'm not sure I see the value in doing that. We're doing basically that automatically every day as daily snapshots (and we verify it in the CI). We know the scripted making of a release "just works".