Hello,

Welcome on board, Carlo!  :-)

Tomas Volf <[email protected]> skribis:

> Maybe a dumb question, but why not grab the key from the keyring branch
> instead?  It has to be up-to-date there by definition

It does not have to be up-to-date; for instance, it might be minimized
(lacking signatures) or it might be expired, since the expiration time
is purposefully ignored for authentication purposes¹.

Ludo’.

¹ https://guix.gnu.org/en/blog/2020/securing-updates/

Reply via email to