On 4 November 2016 at 15:03, Paul G <paul@ganssle.io> wrote:
If the tarballs can be reproducibly created on the github repository, I imagine it would go a long way to say that the "official" distribution is the one that has been signed.

If we're going to use Github more officially, it might make sense to look into their "releases" feature, which is based heavily on Git tags: https://help.github.com/articles/creating-releases/

--
Tim Parenti