Source: libass Version: 0.17.5-1 Severity: normal Hi,
in updating the watch file to a v5 template in commit https://salsa.debian.org/multimedia-team/libass/-/commit/d48f1fc8cad9a743ce05100d5d9dbb98dbf2aa00 it appears the verification of upstream signatures got lost. No check occurs when i run it locally with devscripts 2.26.11~bpo13+1 and there are also open lintian warnings about it: https://udd.debian.org/lintian/?packages=libass<_error=on<_warning=on<_information=on<_pedantic=on<_experimental=on&lintian_tag=#all My naïve attempt to add add a v5 Pgp-Mode and Pgp-Sig-Url-Mangle failed however since the mangled source URL apears to just point to the tag on GitHub itself rather than the actual tarball URL. So unfortunately I don’t have a quick fix to offer, but signature files on GitHub releases seem common enough for some other package to already handle this. Note however, you’ll also need to refresh the upstream keys before the next release since the old version currently stored in debian/upstream/singing-key.asc expired a few days ago. Cheers, Oneric

