We require five signatures on release manifests in order for scripts/verify-install.sh to pass. I think this is excessive, as it usually takes awhile to get the requisite signatures, and sometimes we fail to get enough at all.
To the extent that this script remains desirable at all (I don't really have a good idea about who actually uses it/wants to use it), I think three is plenty, and is a much easier number to realize. So, IMO we should reduce the requisite signatures in the verify-install script accordingly.
We require five signatures on release manifests in order for scripts/verify-install.sh to pass. I think this is excessive, as it usually takes awhile to get the requisite signatures, and sometimes we fail to get enough at all.
To the extent that this script remains desirable at all (I don't really have a good idea about who actually uses it/wants to use it), I think three is plenty, and is a much easier number to realize. So, IMO we should reduce the requisite signatures in the verify-install script accordingly.