On Tue, Jan 06, 2026 at 05:30:32AM +0100, gregor herrmann wrote:
> > > > * debian-watch-does-not-check-openpgp-signature
> > > I disagree.
> > Hmm ok, let's keep this one then.
> :sadface:
> 
> I think this is the lintian tag I hate the most, because (Meta)CPAN doesn't
> support signatures, so I'm seeing this tag for each and every update of a
> Perl package, and I can't do anything about it.

(I do get your sad face but)
surely you can override those?

As I see it, it's sad that (Meta)CPAN doesnt sign the releases, but that
should not cause everybody else to do have equally poor practices?!?

> I remember the times when I had "lintian-clean" packages, and required this
> from new contributors. This ended with the invention of
> debian-watch-does-not-check-openpgp-signature (and since then many other
> questionable/unactionable tags).
 
but why? Adding a line to debian/source/lintian-overrides aint hard, or?
(even if one has to do it for all 3000 perl packages, and especially then,
this can be scripted, no?)

> Oh, and thanks for this cleanup initiative, which seems to go in the
> direction of making me a more happy lintian user again :)

indeed! I also want to be a clean happy lintian user! :)


-- 
cheers,
        Holger

 ⢀⣴⠾⠻⢶⣦⠀
 ⣾⠁⢠⠒⠀⣿⡁  holger@(debian|reproducible-builds|layer-acht).org
 ⢿⡄⠘⠷⠚⠋⠀  OpenPGP: B8BF54137B09D35CF026FE9D 091AB856069AAA1C
 ⠈⠳⣄

Make facts great again.

Attachment: signature.asc
Description: PGP signature

Reply via email to