Feedback for “FAQ”

Open
#190 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
30/100
Issue type
Documentation
Clarity
Mostly clear
Activity status
Stale
Tech stack
fedora

Research direction

Start with the FAQ and download page referenced in the issue, then review how Terra repository installation and package-signing guidance are currently documented. Verify whether the public key can be distributed through a trusted package or signature chain, and update the documentation to explain a secure alternative to --nogpgcheck.

Written by the indexing model from the issue text.

Description

Is there a recommended way to obtain the Terra repo signing public key securely?

For example, is there a "terra" package that can be installed from RPMfusion, or a package like distribution-gpg-keys (on Fedora) that creates a secure chain of signatures?

The download page recommends some command with --nogpgcheck, which is fairly weak. (I assume it relies on trusting both the SSL CA ecosystem and your web servers.)

Dominant language
MDX
Stars
14
Forks
19
Avg merge
7d 12h
Merged PRs (30d)
9

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from FyraLabs/devdocs

All issues in FyraLabs/devdocs

Similar issues

More Documentation issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.