[doap-interest] Auditing Releases

Stuart A. Yeates syeates at gmail.com
Sat Aug 23 22:25:27 BST 2008


There are a couple of relevant issues here:

(a) Reusing existing features is preferable to inventing new ones,
since existing tools can likely do something sensible with existing
features, but getting them to add new features is an uphill battle.
(b) Many geeks recognise a checksum / signature
(c) I believe that mime-type is the correct way to describe the 'type'
of this information

Do you have an alternative idea for the representation?

cheers
stuart


On Sun, Aug 24, 2008 at 2:24 AM, Robert Burrell Donkin
<robertburrelldonkin at blueyonder.co.uk> wrote:
> On Thu, 2008-08-14 at 13:33 +1200, Stuart A. Yeates wrote:
>> I'd be inclined to do this using a mime-typed label, such as:
>>
>> <rdf:Description rdf:about="http://example.com/build-product-1.2.3.zip">
>>     <rdfs:label mime-type="x-sha1-checksum">1234567890ABCDEF</rdfs:label>
>> </rdf:Description>
>
> thanks for the reply
>
> i'd be interested to understand the reasoning behind this recommendation. checksums and signatures are different names for the same artifact but i'm not sure that i'd describe them as particularly human readable.
>
> - robert
>
>> There is a "pgp-signature" mime-type already registered, if you are using that.
>>
>> cheers
>> stuart
>>
>>
>> On Thu, Aug 14, 2008 at 9:34 AM, Robert Burrell Donkin
>> <robertburrelldonkin at blueyonder.co.uk> wrote:
>> > one of my interests is auditing open source releases. anditing and
>> > widely disseminating sums for released artifacts provides defense in
>> > depth against poisoning at source. for example,
>> > http://incubator.apache.org/audit/.
>> >
>> > i plan to add some RDFa instrumentation. if possible, i'd like to reuse
>> > vocabulary. so i wondered whether the DOAP community has any ideas/plans
>> > to extend it's release information to include checksums etc, or (if not)
>> > anyone else had any local conventions for this information.
>> >
>> > - robert
>> >
>> > _______________________________________________
>> > doap-interest mailing list
>> > doap-interest at lists.gnomehack.com
>> > http://lists.usefulinc.com/mailman/listinfo/doap-interest
>> >
>> _______________________________________________
>> doap-interest mailing list
>> doap-interest at lists.gnomehack.com
>> http://lists.usefulinc.com/mailman/listinfo/doap-interest
>>
>
>
> _______________________________________________
> doap-interest mailing list
> doap-interest at lists.gnomehack.com
> http://lists.usefulinc.com/mailman/listinfo/doap-interest
>


More information about the doap-interest mailing list