Bug#1034574: uscan: support OpenPGP signature verification without requiring a saved upstream signing key

2023-04-20 Thread Uwe Kleine-König
Hello, On Tue, Apr 18, 2023 at 05:25:58PM +, John Scott wrote: > I know if you're looking at the subject line alone you'll think I'm proposing > introducing a security vulnerability, but let me explain. > > There are some problems with storing an upstream signing key inside the > package.

Bug#1034574: uscan: support OpenPGP signature verification without requiring a saved upstream signing key

2023-04-18 Thread John Scott
Package: devscripts Version: 2.23.3 Severity: wishlist I know if you're looking at the subject line alone you'll think I'm proposing introducing a security vulnerability, but let me explain. There are some problems with storing an upstream signing key inside the package. It might get stale,