Package: extrepo
Version: 0.14
Severity: normal

apt update with the extrepo-distributed signing key for keybase gives

Warning: An error occurred during the signature verification. The repository is 
not updated and the previous index files will be used. OpenPGP signature 
verification failed: http://prerelease.keybase.io/deb stable InRelease: 
Sub-process /usr/bin/sqv returned an error code (1), error message is: Signing 
key on 222B85B0F90BE2D24CFEB93F47484E50656D16C7 is not bound:            No 
binding signature at time 2026-02-04T01:08:35Z   because: Policy rejected 
non-revocation signature (PositiveCertification) requiring second pre-image 
resistance   because: SHA1 is not considered secure since 2026-02-01T00:00:00Z

The upstream one is OK: 
https://keybase.io/docs/server_security/code_signing_key.asc

-- System Information:
Debian Release: 13.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 
'stable'), (100, 'trixie-fasttrack'), (100, 'trixie-backports-staging')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.12.63+deb13-amd64 (SMP w/8 CPU threads; PREEMPT)
Kernel taint flags: TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages extrepo depends on:
ii  gpgv                       2.4.7-21+deb13u1+b1
ii  libcryptx-perl             0.085-1
ii  libdpkg-perl               1.22.21
ii  libipc-system-simple-perl  1.30-2
ii  libwww-perl                6.78-1
ii  libyaml-libyaml-perl       0.903.0+ds-1
ii  perl                       5.40.1-6

Versions of packages extrepo recommends:
pn  extrepo-offline-data  <none>

extrepo suggests no packages.

-- Configuration Files:
/etc/extrepo/config.yaml changed [not included]

-- no debconf information

Reply via email to