      CVE-2018-12020: add no verbose to avoid fake signatures
      anarcat authored
      The SigSpoof vulnerability found in GnuPG also affects Monkeysign, but
      in a lesser way. We check signatures only in one place: when we import
      images. This is a corner use case that is probably quite uncommon and
      since it requires access to the file in itself, it's likely there are
      already other ways to import arbitrary signatures into monkeysign.
      Still, we play it safe and disable the "verbose" mode that can
      possibly be enabled in `gnupg.conf` as recommended by the reporter,
      Marcus Brinkmann.
      Merge branch 'codes' into '2.x'
      simonft authored
      code of conduct, patches guidelines and glossary
      a few changes to the contributing documentation to adopt the code of conduct (#54), clarify patches guidelines and refer to the modernPGP website.
      See merge request !18
      refer to modernPGP manuals
      anarcat authored
      instead of rewriting our own, try to diverge this effort to a standard, even though that is far from complete
      patches merging guidelines
      anarcat authored
      we try to tell people what is a good patch, and also try to enforce reviews
      this is part of the C4 RFC, which was found to be too complex to use directly
      adopt covenant code of conduct
      anarcat authored
      there was no objections to the code on the mailing list or the issue
      tracker. i wish there was more feedback, but i prefer to commit to
      this than wait longer for responses that may never come.
      we also add the email addresses of two volunteers that stepped forward
      for enforcement.
      Closes: #54
