The Qubes website no longer uses Cloudflare. The question about GitHub
can apply not just to the website but also to the project's use of
GitHub broadly.
- Generalize section from "code" to "repos" (We also have doc repos.)
- Clarify tag and commit signing
- Warn against adding commits on top of unsigned commits
- Warn against trusting GitHub's interface for signature verification
ClosesQubesOS/qubes-issues#3962
As discussed in IRC with marek and h0lger. I've basically summarised what marek said during discussion / from old mailing list thread on same. There appear to be a lot of (to not put too find a point on it) crap discussion on the mailing list about secure boot which may mislead skim reading users. People often ask what binaries they need to sign, so I have included list, but it may be better to omit as we have not tested it (which I've also noted).
As touched on in IRC with holger and marek. New and existing users are often confused about what hardware to buy and whether coreboot is superior to vendor bios. I've tried to keep this entry concise (it could already be considering too long) what I've tried to do is include the most often asked questions without writing a tutorial which is probably out of scope for the Qubes website and better left to the coreboot wiki. I've ignored libreboot here as it is not part of the certified hardware requirements and I don't recall a report of success.