1. 17 Nov, 2020 1 commit
  2. 15 Nov, 2020 1 commit
  3. 11 Nov, 2020 3 commits
  4. 26 Oct, 2020 1 commit
  5. 11 Oct, 2020 1 commit
  6. 08 Oct, 2020 2 commits
  7. 07 Oct, 2020 5 commits
  8. 03 Oct, 2020 1 commit
    • Ludovico de Nittis's avatar
      requirements: Update requirements · d18ed060
      Ludovico de Nittis authored
      The previous version of Twisted that we listed had a couple of CVE
      (CVE-2020-10108 and CVE-2020-10109) that have been fixed in Twisted
      20.3.0.
      
      Even if currently we don't use `requirements.txt`, we might start to do
      it in the future.
      d18ed060
  9. 22 Sep, 2020 1 commit
  10. 19 Sep, 2020 1 commit
  11. 16 Sep, 2020 2 commits
  12. 11 Sep, 2020 8 commits
  13. 10 Sep, 2020 2 commits
  14. 02 Sep, 2020 1 commit
  15. 23 Jul, 2020 1 commit
  16. 13 Jul, 2020 1 commit
  17. 16 Jun, 2020 3 commits
    • Tobias Mueller's avatar
      gpgmeh: raise error if we import a new certificate rather than new sigs · a9bc9fdc
      Tobias Mueller authored
      The attack is subtle and maybe not very relevant:
      Two parties have exchanged their certificates and now one side is
      waiting for the email with the newly produced certifications (aka
      "signatures"). The attacker sends a prepared email with a new
      certificate that it wants the victim to import. Maybe to poison the
      keyring or to make the victim look bad by placing some phishy
      certificates.
      
      This change attempts to detect that and raises an error if it thinks it
      is being tricked.
      a9bc9fdc
    • Tobias Mueller's avatar
      tests: explain who the sender and receiver are · a79c0ef1
      Tobias Mueller authored
      I get confused over the terminology there, so I added a small text that
      will hopefully remind me in the future.
      a79c0ef1
    • Tobias Mueller's avatar
      gpgmeh: Only import via DBus if no homedir was set · 869d2e7b
      Tobias Mueller authored
      The homedir is a GnuPG concept that is not exposed via Seahorse's API.
      If the users wants to make use of that, we fall through to gpgme. We
      might as well not offer a homedir at all to nudge the consumer into
      making use of the gpgme API directly.
      869d2e7b
  18. 15 Jun, 2020 1 commit
  19. 03 Apr, 2020 1 commit
  20. 07 Mar, 2020 1 commit
  21. 11 Feb, 2020 1 commit
    • Tobias Mueller's avatar
      Use pip-tools to have determinisitc dependencies · 6a73f699
      Tobias Mueller authored
      It's not entirely clear yet whether we make good use of the static list
      of dependencies. But if we ever have a CI for building and testing we
      will be able to use the exact package copies to have more reproducible
      results.
      6a73f699
  22. 03 Feb, 2020 1 commit