Adding to this one, 

My workflow is to have my commits to salsa signed by ssh-keys [1] on each 
machine so I can work when travelling on things and sign the commits, then 
upload when I'm home and reunited with my key.

It didn't cross my mind that git-debpush would tag with that key, so my first 
t2u job failed tonight! [2] It makes logical sense, now I've thought about it 
at least.

Making the guard rails a little stronger for forcing GPG and checking keyid 
would be a helpful bonus and avoid little sharp edges like this - I'll know 
next time and do some configuration in the interim.

[1] https://salsa.debian.org/debian-hamradio-team/ax25-apps/-/commit/
3e8c8270d8a7b4d68205efa1f0ed9a2820abda41#
[2] https://tag2upload.debian.org/job/1046
 
Cheers,
Hibby

--
Dave Hibberd <[email protected]>  
Debian Developer
Packet Radioist
MM0RFN

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to